Univention Bugzilla – Bug 54011
gpsd: Multiple issues (4.4)
Last modified: 2021-11-03 16:43:49 CET
New Debian gpsd 3.16-4+deb9u1 fixes: This update addresses the following issue: * gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs. (CVE-2018-17937)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/gpsd_3.16-4.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/gpsd_3.16-4+deb9u1.dsc @@ -1,3 +1,10 @@ +3.16-4+deb9u1 [Tue, 26 Oct 2021 20:33:47 +0300] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload by the LTS team. + * CVE-2018-17937: A stack-based buffer overflow may allow remote + attackers to execute arbitrary code via traffic on port 2947/TCP + or crafted JSON inputs. + 3.16-4 [Fri, 04 Nov 2016 23:35:14 +0100] Bernd Zeimetz <bzed@debian.org>: * [2405f456] Fix debug symbol handling. <http://piuparts.knut.univention.de/4.4-8/#3665050664204782812>
OK: yaml OK: announce_errata OK: patch OK: piuparts
<https://errata.software-univention.de/#/?erratum=4.4x1082>