Bug 1031461 (CVE-2013-5607)
Summary: | CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | barry.gestwicki.ctr, security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | nspr-4.10.2-1.el6_5 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-20 10:42:16 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1031465, 1031898, 1032485, 1032488, 1033524, 1033525 | ||
Bug Blocks: | 1030811 |
Description
Huzaifa S. Sidhpurwala
2013-11-18 03:15:57 UTC
Created nspr tracking bugs for this issue: Affects: fedora-all [bug 1031898] Fixed upstream in NSPR 4.10.2: https://groups.google.com/forum/#!topic/mozilla.dev.tech.nspr/_8AcygMEjSA Upstream bug (currently non-public): https://bugzilla.mozilla.org/show_bug.cgi?id=927687 This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:1791 https://rhn.redhat.com/errata/RHSA-2013-1791.html nspr-4.10.2-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:1829 https://rhn.redhat.com/errata/RHSA-2013-1829.html nspr-4.10.2-1.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report. |