Bug 1361062 - collectd: Unchecked error conditions of gcry_control
Summary: collectd: Unchecked error conditions of gcry_control
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1361063 1361064 1366931 1366932 1366933 1366934
Blocks: 1361065
TreeView+ depends on / blocked
 
Reported: 2016-07-28 09:41 UTC by Adam Mariš
Modified: 2019-09-29 13:54 UTC (History)
22 users (show)

Fixed In Version: collectd 5.4.3, collectd 5.5.2
Clone Of:
Environment:
Last Closed: 2017-01-18 23:38:09 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2016-07-28 09:41:05 UTC
It was found that GCrypt's gcry_control is sometimes called without checking its return value for an error, which may cause the program to be initialized without the desired, secure settings.

Upstream bug:

https://github.com/collectd/collectd/issues/1665

Upstream patch:

https://github.com/collectd/collectd/commit/8b4fed9940e02138b7e273e56863df03d1a39ef7

Comment 1 Adam Mariš 2016-07-28 09:41:48 UTC
Created collectd tracking bugs for this issue:

Affects: fedora-all [bug 1361063]
Affects: epel-all [bug 1361064]

Comment 2 Summer Long 2016-08-12 03:40:27 UTC
Upstream fix, collectd release 5.5.2. 
https://collectd.org/wiki/index.php/Version_5.5

Network plugin: A check for the initialization of secure memory has been added. Previously, failure to initialize this memory was ignored. Thanks to @yujokang. #1665

Comment 3 Fedora Update System 2016-08-12 15:47:37 UTC
collectd-4.10.9-3.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2016-08-15 14:50:41 UTC
collectd-4.10.9-3.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.