Summary: | <sys-libs/cracklib-2.9.6-r1: Stack-based buffer overflow when parsing large GECOS field | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2016/08/16/2 | ||
Whiteboard: | A2 [glsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() Bumped revision with cherry-picked https://github.com/cracklib/cracklib/commit/47e5dec521ab6243c9b249dd65b93d232d90d6b1 and https://github.com/cracklib/cracklib/commit/33d7fa4585247cd2247a1ffa032ad245836c6edb: > commit aac5b4f4a65ce70854e77014fa096b7bd2d34e43 > Author: Thomas Deutschmann > Date: Wed Sep 14 22:55:05 2016 +0200 > > sys-libs/cracklib: Revision bump to address CVE-2016-6318 and another buffer overflow > > Signed-off-by: Lars Wendler > Gentoo-Bug: https://bugs.gentoo.org/591456 > > Package-Manager: portage-2.3.0 > @ Arches, please test and mark stable: =sys-libs/cracklib-2.9.6-r1 Stable targets: alpha amd64 arm hppa ia64 ppc ppc64 x86 sparc amd64 stable Stable on alpha. Stable for HPPA PPC64. arm stable x86 stable sparc stable ppc stable ia64 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one. cleaned up GLSA created. This issue was resolved and addressed in GLSA 201612-25 at https://security.gentoo.org/glsa/201612-25 by GLSA coordinator Aaron Bauman (b-man). |