Bug#907608: libtirpc: CVE-2018-14622: Segmentation fault in makefd_xprt return value in svc_vc.c

2018-08-30 Thread Salvatore Bonaccorso
On Thu, Aug 30, 2018 at 03:35:54PM +0200, Salvatore Bonaccorso wrote:
> Note, there is potentially a CVE duplication here. CVE-2018-14622 and
> CVE-2015-9265 both refer to the same commit.

CVE-2015-9265 has been rejected in favour of CVE-2018-14622.

Regards,
Salvatore



Bug#907608: libtirpc: CVE-2018-14622: Segmentation fault in makefd_xprt return value in svc_vc.c

2018-08-30 Thread Salvatore Bonaccorso
Note, there is potentially a CVE duplication here. CVE-2018-14622 and
CVE-2015-9265 both refer to the same commit.

Regards,
Salvatore



Bug#907608: libtirpc: CVE-2018-14622: Segmentation fault in makefd_xprt return value in svc_vc.c

2018-08-30 Thread Salvatore Bonaccorso
Source: libtirpc
Version: 0.2.5-1
Severity: important
Tags: patch security upstream

Hi,

The following vulnerability was published for libtirpc.

CVE-2018-14622[0]:
Segmentation fault in makefd_xprt return value in svc_vc.c

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-14622
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14622
[1] https://bugzilla.novell.com/show_bug.cgi?id=968175
[2] 
http://git.linux-nfs.org/?p=steved/libtirpc.git;a=commit;h=1c77f7a869bdea2a34799d774460d1f9983d45f0

Regards,
Salvatore