Re: [BLFS Trac] #23152: libgcrypt-1.12.2
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23152: libgcrypt-1.12.2
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: closed
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution: fixed
Keywords: |
-------------------------+-------------------------------
Changes (by Douglas R. Reno):
* resolution: => fixed
* status: new => closed
Comment:
SA-13.0-056 issued
There unfortunately wasn't a CVE assigned for this, which was rather
annoying because there is a *small* remote code execution impact, though
it is mostly squashed by modern hardening in glibc. However it is still a
good denial of service and memory corruption problem. The upstream bug
report is now public.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23152#comment:6>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page