Bug 200545 (CVE-2006-3913)
Summary: | CVE-2006-3913, freeciv: server buffer overflow issues | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Ville Skyttä <scop> |
Component: | freeciv | Assignee: | Brian Pepple <bdpepple> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 5 | CC: | extras-qa, fedora-security-list |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3913 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2006-08-07 19:13:24 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Ville Skyttä
2006-07-28 15:42:00 UTC
Thanks for the bug report. Packages should be available after the next signing/push. The CVE description of the vulnerability mentions three bugs, but the patch applied in latest freeciv package revisions appears to address only two of them. Maybe this is the missing piece? http://svn.gna.org/viewcvs/freeciv?rev=12146&view=rev Yeah, that should be added to my patch. The report stated this was corrected on July 16th, but the changes you referenced weren't applied to svn until July 24th. Seems to be fixed now, thanks. |