Bug 504390 (CVE-2009-1956)
Summary: | CVE-2009-1956 apr-util single NULL byte buffer overflow | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Josh Bressers <bressers> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bojan, jorton, kreilly, mjc |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-06-20 17:10:47 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 504558, 504559, 504560, 504561, 504562, 591930, 595829 | ||
Bug Blocks: |
Description
Josh Bressers
2009-06-06 00:12:12 UTC
The upstream patch can be found here: http://svn.apache.org/viewvc?view=rev&revision=768417 For s390 and ppc, big-endian systems for Red Hat Enterprise Linux, this could be a information disclosure leak: cvss2=4.3/AV:N/AC:M/Au:N/C:P/I:N/A:N For all other architectures of Red Hat Enterprise Linux this has no security impact: cvss2=0 This issue has been addressed in following products: Red Hat Enterprise Linux 3 Via RHSA-2009:1108 https://rhn.redhat.com/errata/RHSA-2009-1108.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 4 Via RHSA-2009:1107 https://rhn.redhat.com/errata/RHSA-2009-1107.html apr-util-1.2.12-7.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report. apr-util-1.3.7-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. apr-util-1.3.7-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. Can this be closed? We don't want to close it yet, feel free to un-CC yourself now that all current Fedora versions are fixed. Thank you! I just saw RHEL and Fedora having fixes, so I thought it was not needed any more. I don't mind the e-mails. This issue has been addressed in following products: Red Hat Certificate System 7.3 Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html |