Possible core using FreeTDS

Bug #1215336 reported by Frediano Ziglio
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
freetds (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

We discovered a bug in FreeTDS up to version 0.91 (the last stable released version).
If you connect to different servers (like MySQL) is possible to cause a core.
As usual server information are usually constant it's hard to use this to get a server DoS but it's still possible.

The patch is at http://gitorious.org/freetds/freetds/commit/748aa264f71aeca777b026f62ff3ce015c7aa682.

Original bug reported by Ramiro Morales in http://lists.ibiblio.org/pipermail/freetds/2013q3/028461.html. Details of problem and fix at http://lists.ibiblio.org/pipermail/freetds/2013q3/028462.html.

information type: Private Security → Public Security
Changed in freetds (Ubuntu):
status: New → Triaged
Steve Langasek (vorlon)
Changed in freetds (Ubuntu):
status: Triaged → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package freetds - 1.00.82-2

---------------
freetds (1.00.82-2) unstable; urgency=medium

  * Fix arch-any builds. Closes: #890888.

 -- Steve Langasek <email address hidden> Tue, 20 Feb 2018 23:46:25 +0000

Changed in freetds (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.