Bug 724480 (CVE-2011-3148, CVE-2011-3149) - VUL-0: CVE-2011-3148 CVE-2011-3149: pam_env multiple issues
Summary: VUL-0: CVE-2011-3148 CVE-2011-3149: pam_env multiple issues
Status: RESOLVED FIXED
Alias: CVE-2011-3148, CVE-2011-3149
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2011-10-31
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard: maint:released:11.3:43858 maint:relea...
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-17 08:20 UTC by Sebastian Krahmer
Modified: 2024-01-29 15:40 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Sebastian Krahmer 2011-10-17 08:26:45 UTC
CVE-2011-3148 (overflow) and CVE-2011-3149 (dos)
Comment 4 Sebastian Krahmer 2011-10-17 08:39:45 UTC
The reproducer perl's should probably read:

perl -e 'print " " x 256, "\\\n";' >> ~/.pam_environment
Comment 19 Bernhard Wiedemann 2011-10-25 13:00:26 UTC
This is an autogenerated message for OBS integration:
This bug (724480) was mentioned in
https://build.opensuse.org/request/show/89277 11.4 / pam
https://build.opensuse.org/request/show/89279 11.3 / pam
https://build.opensuse.org/request/show/89280 Factory / pam
Comment 21 Swamp Workflow Management 2011-11-02 15:44:30 UTC
Update released for: pam, pam-debuginfo, pam-debugsource, pam-devel, pam-doc
Products:
openSUSE 11.4 (debug, i586, x86_64)
Comment 22 Swamp Workflow Management 2011-11-02 15:45:12 UTC
Update released for: pam, pam-debuginfo, pam-debugsource, pam-devel, pam-doc
Products:
openSUSE 11.3 (debug, i586, x86_64)
Comment 23 Ludwig Nussel 2011-11-02 15:46:01 UTC
released
Comment 24 Swamp Workflow Management 2011-11-02 19:08:13 UTC
Update released for: pam, pam-32bit, pam-64bit, pam-debuginfo, pam-devel, pam-devel-32bit, pam-devel-64bit, pam-x86
Products:
SLE-DEBUGINFO 10-SP4 (i386, ia64, ppc, s390x, x86_64)
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 25 Swamp Workflow Management 2011-11-02 19:27:46 UTC
Update released for: pam, pam-32bit, pam-64bit, pam-debuginfo, pam-devel, pam-devel-32bit, pam-devel-64bit, pam-x86
Products:
SLE-DEBUGINFO 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SAP-APL 10-SP3 (x86_64)
SLE-SERVER 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 26 Swamp Workflow Management 2011-11-02 19:55:15 UTC
Update released for: pam, pam-32bit, pam-debuginfo, pam-debuginfo-32bit, pam-debuginfo-x86, pam-debugsource, pam-devel, pam-devel-32bit, pam-doc, pam-x86
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 30 Bernhard Wiedemann 2011-11-03 13:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (724480) was mentioned in
https://build.opensuse.org/request/show/90027 Evergreen:11.2 / pam
Comment 31 Swamp Workflow Management 2011-11-04 10:27:13 UTC
Update released for: pam, pam-devel
Products:
SUSE-CORE 9-SP3-TERADATA (x86_64)
Comment 32 Bernhard Wiedemann 2011-11-04 12:00:32 UTC
This is an autogenerated message for OBS integration:
This bug (724480) was mentioned in
https://build.opensuse.org/request/show/90099 Evergreen:11.1 / pam
Comment 33 Bernhard Wiedemann 2011-11-14 13:00:22 UTC
This is an autogenerated message for OBS integration:
This bug (724480) was mentioned in
https://build.opensuse.org/request/show/91362 Evergreen:11.1 / pam