~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-7869

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2017-04-14
2
 
Candidate: CVE-2017-7869
3
 
PublicDate: 2017-04-14
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7869
6
 
 https://gnutls.org/security.html#GNUTLS-SA-2017-3
7
 
 https://www.gnutls.org/security.html
8
 
 https://usn.ubuntu.com/usn/usn-3318-1
9
 
Description:
10
 
 GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer
11
 
 overflow and heap-based buffer overflow related to the cdk_pkt_read
12
 
 function in opencdk/read-packet.c. This issue (which is a subset of the
13
 
 vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
Bugs:
17
 
 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=420
18
 
Priority: low
19
 
Discovered-by:
20
 
Assigned-to: mdeslaur
21
 
 
22
 
Patches_gnutls26:
23
 
upstream_gnutls26: needs-triage
24
 
precise_gnutls26: ignored (reached end-of-life)
25
 
precise/esm_gnutls26: needed
26
 
trusty_gnutls26: released (2.12.23-12ubuntu2.8)
27
 
vivid/stable-phone-overlay_gnutls26: DNE
28
 
vivid/ubuntu-core_gnutls26: DNE
29
 
xenial_gnutls26: DNE
30
 
yakkety_gnutls26: DNE
31
 
zesty_gnutls26: DNE
32
 
artful_gnutls26: DNE
33
 
bionic_gnutls26: DNE
34
 
devel_gnutls26: DNE
35
 
 
36
 
Patches_gnutls28:
37
 
 upstream: https://gitlab.com/gnutls/gnutls/commit/51464af713d71802e3c6d5ac15f1a95132a354fe
38
 
upstream_gnutls28: released (3.5.8-4)
39
 
precise_gnutls28: ignored (reached end-of-life)
40
 
precise/esm_gnutls28: DNE (precise was needed)
41
 
trusty_gnutls28: needed
42
 
vivid/stable-phone-overlay_gnutls28: ignored (reached end-of-life)
43
 
vivid/ubuntu-core_gnutls28: ignored (reached end-of-life)
44
 
xenial_gnutls28: released (3.4.10-4ubuntu1.3)
45
 
yakkety_gnutls28: released (3.5.3-5ubuntu1.2)
46
 
zesty_gnutls28: released (3.5.6-4ubuntu4.1)
47
 
artful_gnutls28: not-affected (3.5.8-5ubuntu1)
48
 
bionic_gnutls28: not-affected (3.5.8-5ubuntu1)
49
 
devel_gnutls28: not-affected (3.5.8-5ubuntu1)