Bug 1108762 - (CVE-2018-16742) VUL-1: CVE-2018-16742: mgetty: Stack-based buffer overflow in contrib/scrts.c triggered via command line parameter
(CVE-2018-16742)
VUL-1: CVE-2018-16742: mgetty: Stack-based buffer overflow in contrib/scrts.c...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/214328/
CVSSv3:RedHat:CVE-2018-16742:2.9:(A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-09-18 08:04 UTC by Karol Babioch
Modified: 2018-11-02 18:35 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-09-18 08:04:20 UTC
rh#1629971

An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a
stack-based buffer overflow can be triggered via a command-line parameter.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1629971
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-16742
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-16742.html
Comment 3 Swamp Workflow Management 2018-09-25 13:09:48 UTC
SUSE-SU-2018:2850-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1108752,1108756,1108757,1108761,1108762
CVE References: CVE-2018-16741,CVE-2018-16742,CVE-2018-16743,CVE-2018-16744,CVE-2018-16745
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    mgetty-1.1.36-28.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    mgetty-1.1.36-28.3.1
Comment 4 Swamp Workflow Management 2018-09-27 13:21:07 UTC
SUSE-SU-2018:2894-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1108752,1108756,1108757,1108761,1108762
CVE References: CVE-2018-16741,CVE-2018-16742,CVE-2018-16743,CVE-2018-16744,CVE-2018-16745
Sources used:
SUSE Linux Enterprise Module for Basesystem 15 (src):    mgetty-1.1.37-3.3.2
Comment 5 Swamp Workflow Management 2018-09-28 19:09:08 UTC
openSUSE-SU-2018:2942-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1108752,1108756,1108757,1108761,1108762
CVE References: CVE-2018-16741,CVE-2018-16742,CVE-2018-16743,CVE-2018-16744,CVE-2018-16745
Sources used:
openSUSE Leap 15.0 (src):    mgetty-1.1.37-lp150.2.3.1
Comment 6 Swamp Workflow Management 2018-10-02 19:18:00 UTC
SUSE-SU-2018:2979-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1108752,1108756,1108757,1108761,1108762
CVE References: CVE-2018-16741,CVE-2018-16742,CVE-2018-16743,CVE-2018-16744,CVE-2018-16745
Sources used:
SUSE Linux Enterprise Server 12-SP3 (src):    mgetty-1.1.36-58.3.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    mgetty-1.1.36-58.3.1
Comment 7 Marcus Meissner 2018-10-04 15:22:30 UTC
released
Comment 8 Marcus Meissner 2018-10-04 15:25:25 UTC
42.3 missing
Comment 9 Swamp Workflow Management 2018-10-05 15:40:22 UTC
This is an autogenerated message for OBS integration:
This bug (1108762) was mentioned in
https://build.opensuse.org/request/show/640100 42.3 / mgetty
Comment 10 Swamp Workflow Management 2018-10-12 10:11:46 UTC
openSUSE-SU-2018:3108-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1108752,1108756,1108757,1108761,1108762
CVE References: CVE-2018-16741,CVE-2018-16742,CVE-2018-16743,CVE-2018-16744,CVE-2018-16745
Sources used:
openSUSE Leap 42.3 (src):    mgetty-1.1.36-65.3.1
Comment 12 Swamp Workflow Management 2018-10-23 15:11:41 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2018-10-30.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64165
Comment 13 Marcus Meissner 2018-11-02 18:35:37 UTC
dione