Bug 955211
| Summary: | CVE-2013-1950 libtirpc: invalid pointer free leads to crash [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | libtirpc | Assignee: | Steve Dickson <steved> |
| Status: | CLOSED WONTFIX | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 18 | CC: | customercare, jlayton, steved, vdanen |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Release Note | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2013-12-09 14:10:35 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 948378 | ||
|
Description
Jan Lieskovsky
2013-04-22 14:41:43 UTC
Please use the following update submission link to create the Bodhi request for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all associated bugs get updated when new packages are pushed to stable. Please also ensure that the "Close bugs when update is stable" option remains checked. Bodhi update submission link: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=948378,955211 *** Bug 955208 has been marked as a duplicate of this bug. *** Steve, is this fixed in Fedora 19? I can't tell by this: * Mon Apr 22 2013 Steve Dickson <steved> 0.2.3-2 - Update to latest RC release: libtirpc-0-2-4-rc1 (bz 948378) Please advise. We definitely want to see this get fixed in Fedora (including the older releases). Thanks. (In reply to Vincent Danen from comment #3) > Steve, is this fixed in Fedora 19? I can't tell by this: > > * Mon Apr 22 2013 Steve Dickson <steved> 0.2.3-2 > - Update to latest RC release: libtirpc-0-2-4-rc1 (bz 948378) > > Please advise. We definitely want to see this get fixed in Fedora > (including the older releases). Thanks. Yes its in f19..,. https://admin.fedoraproject.org/updates/FEDORA-2013-6262/libtirpc-0.2.3-2.fc19?_csrf_token=2e9273f0392e75d74ca583015d55c60c4a33145b *** Bug 985254 has been marked as a duplicate of this bug. *** The exploit for FC17 0.2.0-19 does also work on FC18 0.2.0-20 . whats with an update for fc18 ? (In reply to customercare from comment #7) > whats with an update for fc18 ? At this point there probably will not be one... |