Bug 1316903 - rpm: Null pointer dereference in rstrdup
Summary: rpm: Null pointer dereference in rstrdup
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=low,public=20160421,reported=2...
Depends On: 1329122
Blocks: 1316905
TreeView+ depends on / blocked
 
Reported: 2016-03-11 12:38 UTC by Adam Mariš
Modified: 2019-06-08 21:04 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-04-25 14:31:44 UTC


Attachments (Terms of Use)

Description Adam Mariš 2016-03-11 12:38:22 UTC
Null pointer dereference in rstrdup triggered by crafted RPM file causing minor crash was reported.

Comment 5 Cedric Buissart 🐶 2016-04-21 09:14:56 UTC
Acknowledgments:

Name: Hanno Boeck

Comment 6 Cedric Buissart 🐶 2016-04-21 09:15:37 UTC
Created rpm tracking bugs for this issue:

Affects: fedora-all [bug 1329122]

Comment 8 Cedric Buissart 🐶 2016-04-25 14:21:11 UTC
Fixed upstream by commit cddf43 :
https://github.com/rpm-software-management/rpm/commit/cddf43a

Comment 9 Cedric Buissart 🐶 2016-04-25 14:30:23 UTC
Red Hat Product Security has determined this issue is not planned to be fixed. If a customer is requesting this fix, please attach any customer contact cases to the bug and email secalert@redhat.com to inform us of the customer request. Product Security will re-open issues with significant customer interest provided they are within support scope.

Comment 10 Fedora Update System 2016-04-26 20:52:42 UTC
rpm-4.13.0-0.rc1.13.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2016-05-07 11:53:45 UTC
rpm-4.13.0-0.rc1.27.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2016-05-22 02:20:19 UTC
rpm-4.12.0.1-17.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.