[Bug 908127] New: firebird server can be forced to segfault by bad packet
http://bugzilla.suse.com/show_bug.cgi?id=908127 Bug ID: 908127 Summary: firebird server can be forced to segfault by bad packet Classification: openSUSE Product: openSUSE Distribution Version: 13.2 Hardware: Other OS: openSUSE 13.2 Status: NEW Severity: Major Priority: P5 - None Component: Other Assignee: bnc-team-screening@forge.provo.novell.com Reporter: mkubecek@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Remote DoS: firebird server segfaults when processing an incorrect packet. Upstream tracker: http://tracker.firebirdsql.org/browse/CORE-4629 Reproducer is not public yet so I'm not going to attach it here for now. Fix has been submitted to SVN, I'm going to test it and provide updated packages. Affected Firebird versions: all 2.1 and 2.5. Affected distributions: all maintained openSUSE, SLED12, SLE12-WE. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=908127 Michal Kubeček <mkubecek@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P2 - High Status|NEW |IN_PROGRESS CC| |bnc-team-gnome@forge.provo. | |novell.com Assignee|bnc-team-screening@forge.pr |mkubecek@suse.com |ovo.novell.com | --- Comment #1 from Michal Kubeček <mkubecek@suse.com> --- Adding SLE maintainer(s) to Cc. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=908127 --- Comment #2 from Michal Kubeček <mkubecek@suse.com> --- Hm... looks like only libfbembed is actually in SLED12 and SLE12-WE so there is probably no need for a SLE12 update. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=908127 Michal Kubeček <mkubecek@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |security-team@suse.de Component|Other |Security -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com