|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-2958: libgda2 syslog format string attack | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Critical | ||
| Priority: | P1 - Urgent | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | CVE-2005-2958: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | Patch for 1.9.x and 1.2.x series | ||
|
Description
Ludwig Nussel
2005-10-26 07:43:05 UTC
Security issue, Rodrigo please look at this immediately. Created attachment 55526 [details]
Patch for 1.9.x and 1.2.x series
Andreas, do we need a swamp ID to submit this fix? A swampid is needed in general but you don't need it to be able to submit fixed packages. http://w3d.suse.de/Dev/Components/Packages/PackMan/pm_pr_fixing_bug.html#pm_pr_fb_bt_security_bugs Maintenance-Tracker-2681 So, should I submit the fixed package to all distributions? I've just submitted it to STABLE and PLUS only. Yes, please backport the fix to all affected libgda versions and submit packages. Package submitted to : INFO: libgda present in /work/src/done/9.0/libgda INFO: libgda present in /work/src/done/9.1/libgda INFO: libgda present in /work/src/done/9.2/libgda INFO: libgda present in /work/src/done/9.3/libgda INFO: libgda present in /work/src/done/10.0/libgda INFO: libgda present in /work/src/done/PLUS/libgda INFO: libgda present in /work/src/done/STABLE/libgda updates released CVE-2005-2958: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) |