Bug ID 956712
Summary VUL-0: CVE-2015-7510: systemd: Stack overflow in nss-mymachines
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.1
Hardware Other
OS Other
Status NEW
Severity Major
Priority P5 - None
Component Security
Assignee systemd-maintainers@suse.de
Reporter abergmann@suse.com
QA Contact qa-bugs@suse.de
Found By Security Response Team
Blocker ---

Only Factory is affected:

rh#1284642

A stack-based buffer overflow vulnerability was found in getpwnam()/getgrnam()
functions of NSS module nss-mymachines provided by systemd.

Public via:
https://github.com/systemd/systemd/issues/2002

Upstream patch:
https://github.com/keszybz/systemd/commit/cb31827d62066a04b02111df3052949fda4b6888

Acknowledgments:
This issue was discovered by Florian Weimer of Red Hat.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1284642
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7510
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7510


You are receiving this mail because: