Bug 853190 (CVE-2013-6050) - VUL-0: CVE-2013-6050: links: integer overflow in parsing of HTML tables
Summary: VUL-0: CVE-2013-6050: links: integer overflow in parsing of HTML tables
Status: RESOLVED FIXED
Alias: CVE-2013-6050
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Berthold Gunreben
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-02 15:49 UTC by Alexander Bergmann
Modified: 2014-05-19 08:43 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2013-12-02 15:49:37 UTC
CVE-2013-6050 was assigned to the following links security issue.

Affected is openSUSE:

12.2: links-2.6 
12.3: links-2.6
13.1: links-2.7

--------------------------------------------------------------------------
Debian Security Advisory DSA-2807-1                   security () debian org
http://www.debian.org/security/                        Moritz Muehlenhoff
November 30, 2013                      http://www.debian.org/security/faq
--------------------------------------------------------------------------

Package        : links2
Vulnerability  : integer overflow
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2013-6050

Mikulas Patocka discovered an integer overflow in the parsing of HTML 
tables in the Links web browser. This can only be exploited when running 
Links in graphical mode.

For the oldstable distribution (squeeze), this problem has been fixed in
version 2.3~pre1-1+squeeze2.

For the stable distribution (wheezy), this problem has been fixed in
version 2.7-1+deb7u1.

For the testing distribution (jessie), this problem has been fixed in
version 2.8-1.

For the unstable distribution (sid), this problem has been fixed in
version 2.8-1.

We recommend that you upgrade your links2 packages.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6050
https://bugzilla.redhat.com/show_bug.cgi?id=1036619
http://seclists.org/fulldisclosure/2013/Nov/217
Comment 1 Swamp Workflow Management 2013-12-03 23:00:12 UTC
bugbot adjusting priority
Comment 2 Thomas Biege 2014-01-09 15:59:37 UTC
patch: https://bugzilla.redhat.com/attachment.cgi?id=831533
Comment 4 Berthold Gunreben 2014-05-19 08:43:07 UTC
fix submitted to network devel project.