Univention Bugzilla – Full Text Bug Listing |
Summary: | libevent: Multiple issues (4.1) | ||
---|---|---|---|
Product: | UCS | Reporter: | Arvid Requate <requate> |
Component: | Security updates | Assignee: | Arvid Requate <requate> |
Status: | CLOSED FIXED | QA Contact: | Daniel Tröder <troeder> |
Severity: | normal | ||
Priority: | P3 | Flags: | requate:
Patch_Available+
|
Version: | UCS 4.1 | ||
Target Milestone: | UCS 4.1-4-errata | ||
Hardware: | Other | ||
OS: | Linux | ||
What kind of report is it?: | Security Issue | What type of bug is this?: | --- |
Who will be affected by this bug?: | --- | How will those affected feel about the bug?: | --- |
User Pain: | Enterprise Customer affected?: | ||
School Customer affected?: | ISV affected?: | ||
Waiting Support: | Flags outvoted (downgraded) after PO Review: | ||
Ticket number: | Bug group (optional): | ||
Max CVSS v3 score: | 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
Bug Depends on: | |||
Bug Blocks: | 43553 |
Description
Arvid Requate
2017-02-15 20:43:32 CET
Imported and built. Advisory: libevent.yaml OK: advisory OK: version dtroeder@dimma:~$ repo_stat.py libevent [..] Version 2.0.19-stable-3+deb7u2 Rev 82812 Date 2017-02-15 20:45:50 Release 4.1-0-0 Scope errata4.1-4 https://security-tracker.debian.org/tracker/source-package/libevent Release Version wheezy 2.0.19-stable-3+deb7u1 wheezy (security) 2.0.19-stable-3+deb7u2 --- Bug wheezy jessie stretch sid Description CVE-2016-10197 fixed fixed vulnerable fixed CVE-2016-10196 fixed fixed vulnerable fixed CVE-2016-10195 fixed fixed vulnerable fixed OK: manual test: root@m90s4:~# univention-install libevent-dev root@m90s4:~# wget https://github.com/libevent/libevent/raw/master/sample/hello-world.c root@m90s4:~# gcc -o libevent-hello-world -levent /usr/share/doc/libevent-dev/examples/hello-world.c root@m90s4:~# ./libevent-hello-world root@m90s4:~# [ 'Hello, World!' = "$(ncat 127.0.0.1 9995)" ] && echo OK OK Actually /usr/share/doc/libevent-dev/examples/hello-world.c was used, not the one from github. |