Bugzilla – Bug 854443
VUL-0: CVE-2013-7038, CVE-2013-7039: libmicrohttpd: memory issues
Last modified: 2017-07-13 14:52:38 UTC
OSS:11636 References: https://bugzilla.redhat.com/show_bug.cgi?id=1039384 https://bugzilla.redhat.com/show_bug.cgi?id=1039390 http://secunia.com/advisories/55903/ https://bugs.gentoo.org/show_bug.cgi?id=493450 http://comments.gmane.org/gmane.comp.security.oss.general/11636
bugbot adjusting priority
Via OSS: There are two more patches I recommend cherry-picking (if you consider the other two worth fixing). All these fixes border on hardening. ------------------------------------------------------------------------ r30927 | grothoff | 2013-11-28 11:05:52 +0100 (Thu, 28 Nov 2013) | 1 line -handle case that original allocation request was zero ------------------------------------------------------------------------ r30926 | grothoff | 2013-11-28 10:16:38 +0100 (Thu, 28 Nov 2013) | 1 line -fix theoretical overflow issue reported by Florian Weimer -- Florian Weimer / Red Hat Product Security Team
> 1) https://bugzilla.redhat.com/show_bug.cgi?id=1039384 Use CVE-2013-7038. > 2) https://bugzilla.redhat.com/show_bug.cgi?id=1039390 Use CVE-2013-7039.
ping cristian?
WIP.. 13.1 is ready..got sidetracked in something else for the rest of the products..
(In reply to Cristian Rodríguez from comment #5) 13.1 is still unpatched, can you please submit?
This is an autogenerated message for OBS integration: This bug (854443) was mentioned in https://build.opensuse.org/request/show/499625 Factory / libmicrohttpd
Submission done.
SUSE-SU-2017:1576-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1041216,854443 CVE References: CVE-2013-7038,CVE-2013-7039 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libmicrohttpd-0.9.30-5.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): libmicrohttpd-0.9.30-5.1 SUSE Linux Enterprise Server 12-SP2 (src): libmicrohttpd-0.9.30-5.1
openSUSE-SU-2017:1676-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1041216,854443 CVE References: CVE-2013-7038,CVE-2013-7039 Sources used: openSUSE Leap 42.2 (src): libmicrohttpd-0.9.30-5.3.1
released