|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-1391: pound buffer overflow | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P5 - None | CC: | joe, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | All | ||
| Whiteboard: | CVE-2005-1391: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | pound-1.8.2-CAN-2005-1391.diff | ||
|
Description
Ludwig Nussel
2005-05-02 07:10:18 UTC
Please tell us whether we are affected and if so start fixing the package. http://w3d.suse.de/Dev/Components/Packages/PackMan/pm_pr_fixing_bug.html#pm_pr_fb_bt_security_bugs ping Pound is on 9.2 and 9.3. I'd suggest to update to 1.9 for both. I don't expect any compatibility issues with that. Did you actually look at the code? It's a one line fix, no version update for that one. Created attachment 38585 [details]
pound-1.8.2-CAN-2005-1391.diff
stripped diff 1.8.2->1.8.3. Only the last hunk is the security fix
(CAN-2005-1391). The first two are bugfixes and probably make sense.
The -1 is not needed in snprintf but upsteam fixed it that way.
SM-Tracker-1456 I've submitted the version update for STABLE. Verified with author that the one-line patch is all we need to fix the issue. I'll submit patched packages for SL 9.2/9.3. aj doesn't want the version upgrade for those. Submitted packages for SL 9.2/9.3. I did mbuild both on the corresponding distro, but it wouldn't hurt if someone double-checked if the packages are ok, as this is my first security fix. ;-) The sad truth is that noone is going to test it. packages released CVE-2005-1391: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) |