Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 553604

Summary: net-mail/checkpw: DoS vulnerability (CVE-2015-0885)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: maintainer-needed, treecleaner
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: ~3 [glsa?]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2015-06-29 23:43:35 UTC
CVE-2015-0885 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0885):
  checkpw 1.02 and earlier allows remote attackers to cause a denial of
  service (infinite loop) via a -- (dash dash) in a username.
Comment 1 Pacho Ramos gentoo-dev 2015-11-05 16:16:16 UTC
Ccing treecleaners
Comment 2 Pacho Ramos gentoo-dev 2016-02-20 17:58:51 UTC
removed
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-02-21 03:59:47 UTC
Package removed per previous comments.  GLSA needed?
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-03-15 08:29:49 UTC
Package removed from tree per [1].

[1]: https://archives.gentoo.org/gentoo-dev/message/67240888bb49c83e26731062d29042e8