Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2019-11365: atftp: A remote attacker may send a crafted packet triggering a stack-based buffer overflow due to an insecurely implemented strncpy call. The vulnerability is trigger | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Major | ||
Priority: | P1 - Urgent | CC: | pmonrealgonzalez, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/230037/ | ||
Whiteboard: | maint:released:sle10-sp3:64272 | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Attachments: |
xx.py
Patch |
Description
Marcus Meissner
2019-04-23 14:21:02 UTC
Created attachment 803417 [details]
xx.py
QA REPRODUCER:
install atftp
gdb atftpd
r --daemon --no-fork --port 69
(should wait)
on another shell on the same host run:
python xx.py
look if atftp has crashed in gdb.
before: gdb will go into Thread 2 "atftpd" received signal SIGSEGV, Segmentation fault. [Switching to Thread 0x7ffff6b5f700 (LWP 17320)] 0x00007ffff7439775 in __strncpy_sse2_unaligned () from /lib64/libc.so.6 (gdb) bt something like that. After it should not get a SEGV. Created attachment 803429 [details]
Patch
Before:
[New Thread 0x7ffff739e700 (LWP 9781)]
Thread 2 "atftpd" received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0x7ffff739e700 (LWP 9781)]
0x00007ffff74397c5 in __strncpy_sse2_unaligned () from /lib64/libc.so.6
After:
[New Thread 0x7ffff739e700 (LWP 9888)]
[Thread 0x7ffff739e700 (LWP 9888) exited]
Updated also in Factory, see: https://build.opensuse.org/request/show/698121 An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2019-05-03. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/64271 SUSE-SU-2019:1091-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1133114,1133145 CVE References: CVE-2019-11365,CVE-2019-11366 Sources used: SUSE OpenStack Cloud 7 (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server for SAP 12-SP2 (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server for SAP 12-SP1 (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server 12-SP4 (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server 12-SP3 (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server 12-SP2-LTSS (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server 12-SP1-LTSS (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Server 12-LTSS (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Desktop 12-SP4 (src): atftp-0.7.0-160.8.1 SUSE Linux Enterprise Desktop 12-SP3 (src): atftp-0.7.0-160.8.1 SUSE Enterprise Storage 4 (src): atftp-0.7.0-160.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2019:14033-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1133114,1133145 CVE References: CVE-2019-11365,CVE-2019-11366 Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): atftp-0.7.0-135.23.3.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): atftp-0.7.0-135.23.3.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): atftp-0.7.0-135.23.3.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): atftp-0.7.0-135.23.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. released This is an autogenerated message for OBS integration: This bug (1133114) was mentioned in https://build.opensuse.org/request/show/902297 15.3 / atftp https://build.opensuse.org/request/show/902298 Backports:SLE-15-SP2 / atftp |