Bug 879057 - (CVE-2012-4426) CVE-2012-4426 mcrypt: multiple format string vulnerabilities
CVE-2012-4426 mcrypt: multiple format string vulnerabilities
Status: CLOSED CURRENTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20120906,repor...
: Security
Depends On: 879108 879109
Blocks:
  Show dependency treegraph
 
Reported: 2012-11-21 18:27 EST by Vincent Danen
Modified: 2015-07-31 02:55 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-11-27 10:13:25 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2012-11-21 18:27:23 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4426 to
the following vulnerability:

Name: CVE-2012-4426
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4426
Assigned: 20120821
Reference: http://www.openwall.com/lists/oss-security/2012/09/06/8
Reference: http://www.openwall.com/lists/oss-security/2012/09/06/9
Reference: http://www.openwall.com/lists/oss-security/2012/09/10/5
Reference: http://www.openwall.com/lists/oss-security/2012/09/13/22

Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier
might allow user-assisted remote attackers to cause a denial of
service (crash) or possibly execute arbitrary code via vectors
involving (1) errors.c or (2) mcrypt.c
Comment 1 Vincent Danen 2012-11-21 23:44:02 EST
The suggested patch is here:

http://www.openwall.com/lists/oss-security/2012/09/06/8
Comment 2 Vincent Danen 2012-11-21 23:46:41 EST
Created mcrypt tracking bugs for this issue

Affects: fedora-all [bug 879108]
Affects: epel-all [bug 879109]
Comment 3 Agostino Sarubbo 2012-11-23 06:34:02 EST
there is a typo in the summary s/mcypt/mcrypt
Comment 4 Tom "spot" Callaway 2012-11-27 10:13:25 EST
We've had this fixed in Fedora and EPEL since 2.6.7, thanks to Pavol Rusnak:
http://sourceforge.net/p/mcrypt/patches/6/

So, this issue does not affect us, I'll close out all these bugs.

Note You need to log in before you can comment on or make changes to this bug.