Summary: | <net-libs/rest-0.7.92-r2: memory corruption when using oauth because of implicit declaration of rest_proxy_call_get_url | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | gnome |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1199049 | ||
Whiteboard: | B3 [noglsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 534012 | ||
Bug Blocks: |
Description
Agostino Sarubbo
![]() Thanks, fixed. +*rest-0.7.92-r2 (05 Mar 2015) + + 05 Mar 2015; Alexandre Rostovtsev <tetromino@gentoo.org> -rest-0.7.91.ebuild, + +rest-0.7.92-r2.ebuild, +files/rest-0.7.92-oauth-missing-include.patch, + +files/rest-0.7.92-tests-GError-pointers.patch, + +files/rest-0.7.92-xml-parser-missing-break.patch: + Fix potentially exploitable memory corruption (bug #542264, thanks to + Agostino Sarubbo). Punt old. Note to arch teams: you will first need to stabilize =net-libs/libsoup-gnome-2.46.0-r1 due to multilib deps. the fixed version is in stable for some time Like already said package is already stable. No vulnerable version left in repository. @ Security: Please vote! GLSA Vote: No |