Bug 1170233 (CVE-2014-9274, CVE-2014-9275)
Summary: | CVE-2014-9274 CVE-2014-9275 unrtf: out-of-bounds memory access vulnerability | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED UPSTREAM | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | carnil, henri, ktdreyer, metherid |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 02:36:59 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1170235, 1170236, 1170237 | ||
Bug Blocks: |
Description
Vincent Danen
2014-12-03 14:36:30 UTC
CVE request on oss-sec here: http://www.openwall.com/lists/oss-security/2014/12/03/4 Created unrtf tracking bugs for this issue: Affects: fedora-all [bug 1170235] Affects: epel-6 [bug 1170236] Affects: epel-7 [bug 1170237] This likely will require more than one CVE, but we'll see what MITRE says/does. Mentioning both reports here is ok as there are no patches available for any of it. MITRE assigned two CVEs (CVE-2014-9274, CVE-2014-9275) to these issues: http://seclists.org/oss-sec/2014/q4/904 Jean-Francois Dockes proposed fixes for both CVEs. CVE-2014-9274 is addressed by https://lists.gnu.org/archive/html/bug-unrtf/2014-12/msg00000.html CVE-2014-9275 is addressed by https://lists.gnu.org/archive/html/bug-unrtf/2014-12/msg00001.html All three changes were incorporated upstream and shipped as a part of unrtf 0.21.6. (http://hg.savannah.gnu.org/hgweb/unrtf/rev/891c2f431c90) So we should just push the newer version (0.21.6 or later) to all Fedora and EPEL branches. unrtf-0.21.7-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report. unrtf-0.21.7-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report. unrtf-0.21.7-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report. This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products. |