Missing security patch leading to stack smashing...

Bug #963407 reported by Edward Fjellskål
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ldns (Ubuntu)
Fix Released
Undecided
Unassigned
Lucid
Won't Fix
Undecided
Unassigned

Bug Description

The bug was reported 2010-01-02 here:
 * https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=292

Missing LDNS_STATUS_DOMAINNAME_OVERFLOW check results in stack smashing parsing packets.

Description: Ubuntu 10.04.3 LTS
Release: 10.04

libldns-dev:
  Installed: 1.6.1-1
  Candidate: 1.6.1-1
  Version table:
 *** 1.6.1-1 0
        500 http://se.archive.ubuntu.com/ubuntu/ lucid/universe Packages
        100 /var/lib/dpkg/status

I expected to have libldns return LDNS_STATUS_DOMAINNAME_OVERFLOW, but instead it smashes the stack leading to a segfault.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

visibility: private → public
visibility: private → public
Changed in ldns (Ubuntu Lucid):
status: New → Triaged
Changed in ldns (Ubuntu):
status: New → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Ubuntu 10.10 and later should be fixed (10.10 has 1.6.4-5).

Revision history for this message
Edward Fjellskal (edwardfjellskaal) wrote : Re: [Bug 963407] Re: Missing security patch leading to stack smashing...

On 03/25/2012 05:51 PM, Jamie Strandboge wrote:
> Ubuntu 10.10 and later should be fixed (10.10 has 1.6.4-5).
>

But 10.04 is LTS....

Update plz :)

E

Revision history for this message
Rolf Leggewie (r0lf) wrote :

lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as "Won't Fix".

Changed in ldns (Ubuntu Lucid):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.