Bug ID | 1208745 |
---|---|
Summary | VUL-1: libmicrohttpd: parser bug that could be used to crash servers using the MHD_PostProcessor |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 15.4 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Minor |
Priority | P5 - None |
Component | Security |
Assignee | security-team@suse.de |
Reporter | Andreas.Stieger@gmx.de |
QA Contact | qa-bugs@suse.de |
Found By | --- |
Blocker | --- |
GNU libmicrohttpd 0.9.76 fixes a security problem in the MHD_PostProcessor where malformed inputs can be used to crash the server (for denial-of-service). Only applies for applications that use the (optional) MHD_PostProcessing logic. References: https://lists.gnu.org/archive/html/libmicrohttpd/2023-02/msg00000.html https://git.gnunet.org/libmicrohttpd.git/commit/?id=6d6846e20bfdf4b3eb1b592c97520a532f724238