Bug 940924 - (CVE-2015-5957) VUL-0: CVE-2015-5957: remind: Buffer overflow in DumpSysVar
(CVE-2015-5957)
VUL-0: CVE-2015-5957: remind: Buffer overflow in DumpSysVar
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
13.2
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
E-mail List
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-08-07 07:45 UTC by Johannes Segitz
Modified: 2015-09-25 12:43 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-08-07 07:45:30 UTC
CVE-2015-5957

remind 3.1.14 and earlier, so all openSUSE


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5957
http://seclists.org/oss-sec/2015/q3/304
Comment 1 Swamp Workflow Management 2015-08-07 22:00:16 UTC
bugbot adjusting priority
Comment 2 Petr Uzel 2015-08-14 15:30:27 UTC
Fixes submitted to 13.1 and 13.2 (sr#323183, sr#323182)
Comment 3 Petr Uzel 2015-08-14 15:34:36 UTC
And remind-3.1.15 (which has the fix) submitted to Factory. Closing the bug.
Comment 5 Bernhard Wiedemann 2015-08-14 16:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (940924) was mentioned in
https://build.opensuse.org/request/show/323182 13.2 / remind
https://build.opensuse.org/request/show/323183 13.1 / remind
Comment 7 Marcus Meissner 2015-09-04 15:24:53 UTC
can you add the patchfilenames to the .changs entries, opensuse is quiet strict for this
Comment 8 Petr Uzel 2015-09-08 22:14:44 UTC
Resubmitted, this time with patch filename in .changes.
Comment 9 Bernhard Wiedemann 2015-09-08 23:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (940924) was mentioned in
https://build.opensuse.org/request/show/329790 13.1 / remind
https://build.opensuse.org/request/show/329791 13.2 / remind
Comment 10 Swamp Workflow Management 2015-09-19 08:09:55 UTC
openSUSE-SU-2015:1579-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 940924
CVE References: CVE-2015-5957
Sources used:
openSUSE 13.2 (src):    remind-3.1.13-4.3.1
openSUSE 13.1 (src):    remind-3.1.13-2.3.1
Comment 11 Marcus Meissner 2015-09-25 12:43:08 UTC
rfeleased