Bug ID | 956712 |
---|---|
Summary | VUL-0: CVE-2015-7510: systemd: Stack overflow in nss-mymachines |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 42.1 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Major |
Priority | P5 - None |
Component | Security |
Assignee | systemd-maintainers@suse.de |
Reporter | abergmann@suse.com |
QA Contact | qa-bugs@suse.de |
Found By | Security Response Team |
Blocker | --- |
Only Factory is affected: rh#1284642 A stack-based buffer overflow vulnerability was found in getpwnam()/getgrnam() functions of NSS module nss-mymachines provided by systemd. Public via: https://github.com/systemd/systemd/issues/2002 Upstream patch: https://github.com/keszybz/systemd/commit/cb31827d62066a04b02111df3052949fda4b6888 Acknowledgments: This issue was discovered by Florian Weimer of Red Hat. References: https://bugzilla.redhat.com/show_bug.cgi?id=1284642 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7510 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7510