Bug 625835 (CVE-2011-1071) - VUL-0: CVE-2011-1071: glibc: fnmatch() buffer overflow
Summary: VUL-0: CVE-2011-1071: glibc: fnmatch() buffer overflow
Status: RESOLVED FIXED
: 695840 (view as bug list)
Alias: CVE-2011-1071
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2011-03-28
Assignee: Michael Matz
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:40934 maint:...
Keywords:
Depends on:
Blocks: 695840
  Show dependency treegraph
 
Reported: 2010-07-27 08:00 UTC by Thomas Biege
Modified: 2019-05-01 15:22 UTC (History)
6 users (show)

See Also:
Found By: Development
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Petr Baudis 2010-07-28 07:11:46 UTC
Yeah, I have seen couple of various alloca bugs in glibc before; it would be good to go through all of them in glibc sometime and audit them...

FYI, I'm on vacation until Aug 8 - if you think this should be dealt with before, perhaps the best person to contact would be Michael Matz.
Comment 4 Thomas Biege 2010-08-09 07:55:09 UTC
mass change P5->P3
Comment 5 Sebastian Krahmer 2010-11-03 10:21:49 UTC
any news here? Maybe rather something for upstream?
Comment 6 Thomas Biege 2010-11-09 12:34:45 UTC
Petr?
Comment 7 Petr Baudis 2010-11-09 12:52:38 UTC
There is a fix for this in glibc git, but it has multiple bugs in it. I'm currently trying to sort it out with Ulrich. It would be best to include this in the upcoming next glibc maintenace update.
Comment 8 Thomas Biege 2010-11-10 11:18:28 UTC
I prefer a security update.
Comment 10 Marcus Meissner 2011-03-02 08:25:38 UTC
petr, any news on this bug? has upstream found a good fix?
Comment 11 Ludwig Nussel 2011-03-02 08:36:56 UTC
according to http://sourceware.org/bugzilla/show_bug.cgi?id=11883 a fix is upstream.
Comment 13 Swamp Workflow Management 2011-03-14 08:01:44 UTC
The SWAMPID for this issue is 39331.
This issue was rated as moderate.
Please submit fixed packages until 2011-03-28.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 14 Sebastian Krahmer 2011-04-12 07:12:19 UTC
There is yet another fnmatch issue as it seems:

Name: CVE-2011-1659
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1659

Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or
libc6) 2.13 and earlier allows context-dependent attackers to cause a
denial of service (application crash) via a long UTF8 string that is
used in an fnmatch call with a crafted pattern argument, a different
vulnerability than CVE-2011-1071.


Current Votes:
None (candidate not yet proposed)
Comment 16 Petr Baudis 2011-05-12 15:48:35 UTC
Submitted everywhere now, including Sebastian's new find.
Comment 33 Marcus Meissner 2011-06-27 13:37:03 UTC
finally released, thanks!
Comment 34 Swamp Workflow Management 2011-06-27 15:15:42 UTC
Update released for: glibc, glibc-32bit, glibc-debuginfo, glibc-debuginfo-32bit, glibc-debuginfo-64bit, glibc-debuginfo-x86, glibc-debugsource, glibc-devel, glibc-devel-32bit, glibc-html, glibc-i18ndata, glibc-info, glibc-locale, glibc-locale-32bit, glibc-locale-x86, glibc-obsolete, glibc-profile, glibc-profile-32bit, glibc-profile-x86, glibc-x86, nscd
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-SDK 11-SP1 (i386, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 35 Swamp Workflow Management 2011-06-27 15:56:15 UTC
Update released for: glibc, glibc-32bit, glibc-64bit, glibc-dceext, glibc-dceext-32bit, glibc-dceext-64bit, glibc-dceext-devel, glibc-dceext-x86, glibc-debuginfo, glibc-devel, glibc-devel-32bit, glibc-devel-64bit, glibc-html, glibc-i18ndata, glibc-info, glibc-locale, glibc-locale-32bit, glibc-locale-64bit, glibc-locale-x86, glibc-obsolete, glibc-profile, glibc-profile-32bit, glibc-profile-64bit, glibc-profile-x86, glibc-x86, nscd
Products:
SLE-DEBUGINFO 10-SP4 (i386, ia64, ppc, s390x, x86_64)
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SDK 10-SP4 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 36 Swamp Workflow Management 2011-06-27 17:13:29 UTC
Update released for: glibc, glibc-devel, glibc-html, glibc-i18ndata, glibc-info, glibc-locale, glibc-profile, nscd, timezone
Products:
Novell-Linux-POS 9 (i386)
Open-Enterprise-Server 9 (i386)
SUSE-CORE 9 (i386, ia64, ppc, s390, s390x, x86_64)
Comment 37 Leonardo Chiquitto 2011-06-30 17:47:39 UTC
*** Bug 695840 has been marked as a duplicate of this bug. ***