Bug 1992805 (CVE-2020-21675)
Summary: | CVE-2020-21675 transfig: A stack-based buffer overflow in the genptk_text component in genptk.c could result in a denial of service | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Michael Kaplan <mkaplan> |
Component: | vulnerability | Assignee: | Nobody <nobody> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | databases-maint, hhorak, kasal, mschorm, pkubat |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2023-12-13 13:42:53 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2000748, 2000749 | ||
Bug Blocks: | 1992794 |
Description
Michael Kaplan
2021-08-11 18:40:21 UTC
Hi, can you please create a tracking issues for a specific versions of RHEL/Fedora, which are affected by the newly created CVEs? I see multiple CVE trackers created recently and for the process of backporting the fixes to continue correctly, we need tracker for every affected version for every CVE. Can you please handle this ? From the first sight, I assume rhel-9 and Fedora should be affected. Thanks. In reply to comment #1: > Hi, > > can you please create a tracking issues for a specific versions of > RHEL/Fedora, which are affected by the newly created CVEs? I see multiple > CVE trackers created recently and for the process of backporting the fixes > to continue correctly, we need tracker for every affected version for every > CVE. Can you please handle this ? From the first sight, I assume rhel-9 and > Fedora should be affected. > > Thanks. Hey, Based on our Manifest and version Fedora doesn't seem affected. This is shipped in Fedora(fedora:34/transfig-3.2.8a-2.fc34) rhel-9 is probably affected, Other rhel versions need to be checked over by analysts first I can create rhel-9 trackers, wondering if it's fine for you to have all the cves linked into one tracker bug or do prefer separate trackers? Hi, One tracker should be enough, thank you. |