Bug 625547 (CVE-2010-2546) - VUL-0: CVE-2010-2546: libmikmod: mikmod incomplete fix for CVE-2009-3995
Summary: VUL-0: CVE-2010-2546: libmikmod: mikmod incomplete fix for CVE-2009-3995
Status: RESOLVED FIXED
: CVE-2010-2971 (view as bug list)
Alias: CVE-2010-2546
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2010-08-10
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:planned:update
Keywords:
Depends on:
Blocks:
 
Reported: 2010-07-26 13:10 UTC by Thomas Biege
Modified: 2020-08-19 15:53 UTC (History)
3 users (show)

See Also:
Found By: Development
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2010-07-26 13:10:43 UTC
Hi.
There is a security bug in package 'libmikmod'.

This information is from 'oss-security'.

This bug is public.

There is no coordinated release date (CRD) set.

More information can be found here:
	https://sourceforge.net/tracker/?func=detail&aid=3033086&group_id=40531&atid=428227

CVE number: CVE-2009-3995
CVE description: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3995

Original posting:


----------  Weitergeleitete Nachricht  ----------

Betreff: [oss-security] mikmod incomplete fix for CVE-2009-3995
Datum: Freitag 23 Juli 2010, 11:08:12
Von: Tomas Hoger <thoger@redhat.com>
An:  OSS Security <oss-security@lists.openwall.com>

Upstream fix created to address CVE-2009-3995 does not address the
flaw properly.  See upstream bug for details:

https://sourceforge.net/tracker/?func=detail&aid=3033086&group_id=40531&atid=428227

-- 
Tomas Hoger / Red Hat Security Response Team

-------------------------------------------------------------
Comment 1 Thomas Biege 2010-07-27 08:16:38 UTC
CVE-2010-2546
Comment 2 Swamp Workflow Management 2010-07-27 08:59:02 UTC
The SWAMPID for this issue is 34774.
This issue was rated as moderate.
Please submit fixed packages until 2010-08-10.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 3 Thomas Biege 2010-07-27 16:00:31 UTC
CVE-2009-3995: CVSS v2 Base Score: 9.3 (HIGH) (AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVE-2009-3995: Buffer Errors (CWE-119)
Comment 4 Ludwig Nussel 2010-08-02 14:48:54 UTC
the patch we have for libmikmod is almost correct. It uses ENVPOINTS(32) instead of ITENVCNT(25) though *grmbl. close enough to make this a planned update only IMHO.
Comment 5 Thomas Biege 2010-08-09 07:55:22 UTC
mass change P5->P3
Comment 6 Pavol Rusnak 2010-08-25 13:30:54 UTC
Fixed in:

11.1 - SR # 46209
11.2 - SR # 46210
11.3 - SR # 46211
Factory - SR # 46212
Comment 7 Pavol Rusnak 2010-08-25 15:31:54 UTC
Submitted to:
* SLE11
* SLE10-SP3
* SLES9
Comment 8 Stefan Behlert 2011-04-14 13:24:14 UTC
Thomas, the correct fix has been submitted, should we release it now or keep it in planned update until we have another fix for the package?
Comment 9 Ludwig Nussel 2011-04-14 13:42:51 UTC
keep as planned update
Comment 10 Ludwig Nussel 2012-06-29 07:44:12 UTC
*** Bug 752802 has been marked as a duplicate of this bug. ***
Comment 11 Bernhard Wiedemann 2016-04-15 12:51:58 UTC
This is an autogenerated message for OBS integration:
This bug (625547) was mentioned in
https://build.opensuse.org/request/show/46212 Factory / libmikmod
Comment 12 Marcus Meissner 2017-07-13 10:04:51 UTC
Scott, the package is desktop specific and frederic told me to assign to gnome maintainers.

Can you declare a bugowner too for this?
Comment 13 Scott Reeves 2017-09-06 00:04:09 UTC
(In reply to Marcus Meissner from comment #12)
> Scott, the package is desktop specific and frederic told me to assign to
> gnome maintainers.
> 
> Can you declare a bugowner too for this?

Hi Marcus - I submitted the bugowner request a few weeks ago and it was accepted today so I will move this back to the security team.
Comment 15 Scott Reeves 2018-04-23 21:59:35 UTC
submitted for SLE11 - #162703.
Comment 17 Swamp Workflow Management 2018-05-30 13:13:05 UTC
SUSE-SU-2018:1471-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 625547
CVE References: CVE-2009-3995,CVE-2010-2546
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    libmikmod-3.1.11a-116.2.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    libmikmod-3.1.11a-116.2.3.1
Comment 18 Marcus Meissner 2020-08-19 15:53:17 UTC
done