Summary: | <net-libs/nghttp2-1.31.1: Denial of service due to NULL pointer dereference (CVE-2018-1000168) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | polynomial-c |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1/ | ||
See Also: | https://bugs.gentoo.org/show_bug.cgi?id=646100 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
=net-libs/nghttp2-1.31.1
|
Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
![]() commit 88c85f32a68ff188cb9f815ea67112a1d1a8e476 Author: Jeroen Roovers <jer@gentoo.org> Date: Fri Apr 13 06:23:20 2018 net-libs/nghttp2: Version 1.31.1. Package-Manager: Portage-2.3.28, Repoman-2.3.9 The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9bd6daf026ab5608fa5da75e2da0e75fa4174735 commit 9bd6daf026ab5608fa5da75e2da0e75fa4174735 Author: Rolf Eike Beer <eike@sf-mail.de> AuthorDate: 2018-04-13 19:57:33 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-04-13 20:07:41 +0000 net-libs/nghttp2: stable 1.31.1 for sparc Bug: https://bugs.gentoo.org/653066 Package-Manager: Portage-2.3.24, Repoman-2.3.6 RepoMan-Options: --include-arches="sparc" net-libs/nghttp2/nghttp2-1.31.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)} The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9f283f1e604a0a52460b47e393b16ec093f8843c commit 9f283f1e604a0a52460b47e393b16ec093f8843c Author: Aaron Bauman <bman@gentoo.org> AuthorDate: 2018-04-14 14:52:29 +0000 Commit: Aaron Bauman <bman@gentoo.org> CommitDate: 2018-04-14 14:54:15 +0000 net-libs/nghttp2: amd64 stable Bug: https://bugs.gentoo.org/653066 Package-Manager: Portage-2.3.28, Repoman-2.3.9 net-libs/nghttp2/nghttp2-1.31.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)} arm64 stable x86 stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bfe84eb0195242e899a8c9216b08acf7b860e9a3 commit bfe84eb0195242e899a8c9216b08acf7b860e9a3 Author: Sergei Trofimovich <slyfox@gentoo.org> AuthorDate: 2018-04-18 21:38:21 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-04-18 21:38:49 +0000 net-libs/nghttp2: stable 1.31.1 for ia64, bug #653066 Bug: https://bugs.gentoo.org/653066 Package-Manager: Portage-2.3.28, Repoman-2.3.9 RepoMan-Options: --include-arches="ia64" net-libs/nghttp2/nghttp2-1.31.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)} alpha stable arm stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2c59d7bba8ae474c62450bf174a10151bd0ab931 commit 2c59d7bba8ae474c62450bf174a10151bd0ab931 Author: Sergei Trofimovich <slyfox@gentoo.org> AuthorDate: 2018-05-11 22:41:39 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-05-11 22:43:06 +0000 net-libs/nghttp2: stable 1.31.1 for ppc64, bug #653066 Bug: https://bugs.gentoo.org/653066 Package-Manager: Portage-2.3.36, Repoman-2.3.9 RepoMan-Options: --include-arches="ppc64" net-libs/nghttp2/nghttp2-1.31.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c299b80835911d59d860d4e07dd82745768d0c47 commit c299b80835911d59d860d4e07dd82745768d0c47 Author: Sergei Trofimovich <slyfox@gentoo.org> AuthorDate: 2018-07-15 10:00:10 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-07-15 10:24:31 +0000 net-libs/nghttp2: stable 1.31.1 for ppc, bug #653066 Bug: https://bugs.gentoo.org/653066 Package-Manager: Portage-2.3.42, Repoman-2.3.9 RepoMan-Options: --include-arches="ppc" net-libs/nghttp2/nghttp2-1.31.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) Security cleanup has already been performed. tree is clean |