Bug 914891 (CVE-2014-9637) - VUL-1: CVE-2014-9637 patch: local denial of service with a crafted patch
Summary: VUL-1: CVE-2014-9637 patch: local denial of service with a crafted patch
Status: RESOLVED FIXED
Alias: CVE-2014-9637
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113127/
Whiteboard: CVSSv2:NVD:CVE-2014-9637:7.1:(AV:N/AC...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-27 09:54 UTC by Victor Pereira
Modified: 2020-05-12 17:44 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
Reproducer (1.80 KB, application/x-gzip)
2015-02-04 08:58 UTC, Johannes Segitz
Details

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2015-01-27 23:00:15 UTC
bugbot adjusting priority
Comment 2 Johannes Segitz 2015-02-04 08:58:20 UTC
Created attachment 621822 [details]
Reproducer
Comment 3 Jean Delvare 2015-02-16 12:05:37 UTC
Note: the upstream commit only fixes the segfault. Patch still runs out of memory and fails. Memory consumption still reaches insane amounts (8 GB on my 4 GB memory machine according to valgrind.)

So this bug is still not fully fixed upstream.

Also, I don't quite see how this qualifies as a security incident.
Comment 4 Swamp Workflow Management 2018-05-07 19:08:21 UTC
SUSE-SU-2018:1162-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1059698,1080918,1088420,662957,914891
CVE References: CVE-2010-4651,CVE-2014-9637,CVE-2016-10713,CVE-2018-1000156
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    patch-2.5.9-252.22.7.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    patch-2.5.9-252.22.7.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    patch-2.5.9-252.22.7.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    patch-2.5.9-252.22.7.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    patch-2.5.9-252.22.7.1
Comment 5 Wolfgang Frisch 2020-01-15 10:56:33 UTC
Fixed.