Bugzilla – Bug 965810
VUL-0: CVE-2016-1526: graphite2: DoS
Last modified: 2016-06-08 12:25:02 UTC
CVE-2016-1526 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1526 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1526.html
bugbot adjusting priority
This bug is probably related to second part of 'Denial of Service'. Which commit is supposed to fix this issue? Thank you
Only gr_feature_ref* pfeatureref is ever passed out, but there is never defined how gr_feature_ref is built of, so it is only ever used as a pointer. -> is ok to change size internally. The rest also just seem to change internal details, not exposed apis.
for a versipon update we would need to look at the diff again.
Created attachment 667659 [details] patch against 1.3.1 Four of these seven commits from comment 5 was already in 1.3.1.
This is an autogenerated message for OBS integration: This bug (965810) was mentioned in https://build.opensuse.org/request/show/367416 13.2 / graphite2
Packages submitted.
SUSE-SU-2016:0779-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 965803,965807,965810 CVE References: CVE-2016-1521,CVE-2016-1523,CVE-2016-1526 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP1 (src): graphite2-1.3.1-6.1 SUSE Linux Enterprise Software Development Kit 12 (src): graphite2-1.3.1-6.1 SUSE Linux Enterprise Server 12-SP1 (src): graphite2-1.3.1-6.1 SUSE Linux Enterprise Server 12 (src): graphite2-1.3.1-6.1 SUSE Linux Enterprise Desktop 12-SP1 (src): graphite2-1.3.1-6.1 SUSE Linux Enterprise Desktop 12 (src): graphite2-1.3.1-6.1
openSUSE-SU-2016:0791-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 965803,965806,965807,965810 CVE References: CVE-2016-1521,CVE-2016-1522,CVE-2016-1523,CVE-2016-1526 Sources used: openSUSE 13.2 (src): graphite2-1.2.4-2.4.1
released
openSUSE-SU-2016:0875-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 965803,965807,965810 CVE References: CVE-2016-1521,CVE-2016-1523,CVE-2016-1526 Sources used: openSUSE Leap 42.1 (src): graphite2-1.3.1-3.1