Univention Bugzilla – Bug 52822
libbsd: Multiple issues (4.4)
Last modified: 2021-03-17 13:59:57 CET
New Debian libbsd 0.8.3-1+deb9u1 fixes: This update addresses the following issue: * nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab). (CVE-2019-20367)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/libbsd_0.8.3-1.dsc +++ apt/ucs_4.4-0-errata4.4-7/source/libbsd_0.8.3-1+deb9u1.dsc @@ -1,3 +1,10 @@ +0.8.3-1+deb9u1 [Thu, 18 Feb 2021 20:03:02 +0100] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2019-20367 + A non-NUL terminated symbol name in the string table might + result in a out-of-bounds read. + 0.8.3-1 [Sat, 23 Apr 2016 11:11:35 +0200] Guillem Jover <guillem@debian.org>: * New upstream release. <http://piuparts.knut.univention.de/4.4-7/#6885572540273536323>
OK: yaml OK: announce_errata OK: patch OK: piuparts
<https://errata.software-univention.de/#/?erratum=4.4x912>