Bug 367471 (CVE-2007-5197) - CVE-2007-5197: mono Math.BigInteger buffer overflow
Summary: CVE-2007-5197: mono Math.BigInteger buffer overflow
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-5197
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Alexander Larsson
QA Contact: Fedora Extras Quality Assurance
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard:
Depends On: 367531 367541 367551 367571
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-11-05 21:08 UTC by Ville Skyttä
Modified: 2007-12-20 12:01 UTC (History)
2 users (show)

Fixed In Version: 1.2.5.1-2.fc8
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-12-20 12:01:33 UTC
Embargoed:


Attachments (Terms of Use)
Patch from Debian (1.35 KB, patch)
2007-11-05 21:08 UTC, Ville Skyttä
no flags Details | Diff

Description Ville Skyttä 2007-11-05 21:08:43 UTC
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5197

"Buffer overflow in the Mono.Math.BigInteger class in Mono allows
context-dependent attackers to execute arbitrary code via unspecified vectors."

Patch extracted from Debian's 1.2.2.1-1etch1 patchkit (attached) seems to apply
to 1.2.5.1 in devel with some line offsets, I have done no further analysis.

Comment 1 Ville Skyttä 2007-11-05 21:08:43 UTC
Created attachment 248611 [details]
Patch from Debian

Comment 2 Lubomir Kundrak 2007-11-05 21:47:10 UTC
Gentoo also has a patch, maybe a different one
http://bugs.gentoo.org/show_bug.cgi?id=197067

Comment 3 Fedora Update System 2007-11-08 06:01:20 UTC
mono-1.2.5.1-2.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Lubomir Kundrak 2007-11-09 18:16:23 UTC
Alex: I'd urge this a bit. When are f6 and f7 versions likely to hit the
repositories? (I've noticed there was some issue with libs on 64 bit platforms..?)

Comment 5 Fedora Update System 2007-11-09 23:55:05 UTC
mono-1.2.3-5.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.