[Bug 1208745] New: VUL-1: libmicrohttpd: parser bug that could be used to crash servers using the MHD_PostProcessor
http://bugzilla.opensuse.org/show_bug.cgi?id=1208745 Bug ID: 1208745 Summary: VUL-1: libmicrohttpd: parser bug that could be used to crash servers using the MHD_PostProcessor Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: Andreas.Stieger@gmx.de QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- GNU libmicrohttpd 0.9.76 fixes a security problem in the MHD_PostProcessor where malformed inputs can be used to crash the server (for denial-of-service). Only applies for applications that use the (optional) MHD_PostProcessing logic. References: https://lists.gnu.org/archive/html/libmicrohttpd/2023-02/msg00000.html https://git.gnunet.org/libmicrohttpd.git/commit/?id=6d6846e20bfdf4b3eb1b592c... -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1208745 http://bugzilla.opensuse.org/show_bug.cgi?id=1208745#c6 --- Comment #6 from Andreas Stieger <Andreas.Stieger@gmx.de> --- Write-up: https://github.com/0xhebi/CVEs/blob/main/GNU%20Libmicrohttpd/CVE-2023-27371.... -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com