First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 154315
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 153495
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
OpenPBS_2_3_16-security.diff OpenPBS_2_3_16-security.diff patch Sune Kloppenborg Jeppesen 2006-11-06 23:39 0000 4.34 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 154315 depends on: Show dependency tree
Bug 154315 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-11-06 23:38 0000
Untested patch from Thomas Biege.

summary:
- strncpy() off-by-one
- return value check for setuid()
- zero'ize rbuf
- off-by-one in while (cp < &rbuf[BUFSIZ] && ch != '\n'); 
- verify/limit values of: size, blksize, need

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-11-06 23:39:18 0000 -------
Created an attachment (id=101375) [details]
OpenPBS_2_3_16-security.diff

------- Comment #2 From Matthias Geerdsen 2006-11-07 03:17:48 0000 -------
is this http://secunia.com/advisories/22637/ :: 
CVE-2006-5616 ::
http://lists.suse.com/archive/suse-security-announce/2006-Oct/0007.html
?

------- Comment #3 From Sune Kloppenborg Jeppesen 2006-11-07 11:55:28 0000 -------
Seems to be the same, though I didn't check wether the patches match.

------- Comment #4 From Raphael Marichez 2006-11-10 05:19:19 0000 -------

*** This bug has been marked as a duplicate of 153495 ***

First Last Prev Next    No search results available      Search page      Enter new bug