Bugzilla – Bug 954199
VUL-0: CVE-2015-8080: redis: Integer wraparound in lua_struct.c causing stack-based buffer overflow
Last modified: 2016-11-11 14:43:35 UTC
opensuse only: An Integer wraparound in lua_struct.c can cause a stack-based buffer overflow. rh#1278965 References: https://bugzilla.redhat.com/show_bug.cgi?id=1278965 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8080
is upstream for the library, redis "just" ships a copy. http://www.inf.puc-rio.br/~roberto/struct/
bugbot adjusting priority
probably valid. but if we find that library in other places as well. we should fix it there too.
openSUSE-SU-2016:1444-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 954199 CVE References: CVE-2015-8080 Sources used: openSUSE Leap 42.1 (src): redis-3.0.4-3.1 openSUSE 13.2 (src): redis-2.8.22-2.9.1
no sles copy. opensuse done.