please fix CVE-2014-5119
Bug #1362409 reported by
Jamie Strandboge
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
eglibc (Ubuntu) |
Won't Fix
|
Undecided
|
Unassigned | ||
Lucid |
Fix Released
|
High
|
Adam Conrad | ||
Precise |
Fix Released
|
High
|
Adam Conrad | ||
Trusty |
Fix Released
|
High
|
Adam Conrad | ||
Utopic |
Won't Fix
|
Undecided
|
Unassigned | ||
glibc (Ubuntu) |
Fix Released
|
High
|
Adam Conrad | ||
Utopic |
Fix Released
|
High
|
Adam Conrad |
Changed in eglibc (Ubuntu Utopic): | |
status: | New → Won't Fix |
no longer affects: | glibc (Ubuntu Lucid) |
no longer affects: | glibc (Ubuntu Precise) |
no longer affects: | glibc (Ubuntu Trusty) |
Changed in eglibc (Ubuntu): | |
status: | New → Won't Fix |
Changed in eglibc (Ubuntu Lucid): | |
status: | New → In Progress |
importance: | Undecided → High |
assignee: | nobody → Adam Conrad (adconrad) |
Changed in eglibc (Ubuntu Precise): | |
status: | New → In Progress |
importance: | Undecided → High |
assignee: | nobody → Adam Conrad (adconrad) |
Changed in eglibc (Ubuntu Trusty): | |
status: | New → In Progress |
importance: | Undecided → High |
assignee: | nobody → Adam Conrad (adconrad) |
Changed in glibc (Ubuntu Utopic): | |
status: | New → In Progress |
importance: | Undecided → High |
assignee: | nobody → Adam Conrad (adconrad) |
information type: | Public → Public Security |
To post a comment you must log in.
This bug was fixed in the package eglibc - 2.15-0ubuntu10.7
---------------
eglibc (2.15-0ubuntu10.7) precise; urgency=medium
* SECURITY UPDATE: heap overflow in __gconv_ translit_ find() (LP: #1362409) patches/ any/cvs- CVE-2014- 5119.diff: Backport upstream commit to patches/ any/submitted- CVE-2014- 0475.diff: update with a backport
- debian/
completely remove support for loadable gconv transliteration modules.
* SECURITY REGRESSION: localplt regression introduced in 2.15-0ubuntu10.6
- debian/
of upstream commit ca38dc17 to include memmem hidden alias declaration.
-- Adam Conrad <email address hidden> Wed, 27 Aug 2014 22:18:52 -0600