public inbox for glibc-bugs@sourceware.org
help / color / mirror / Atom feed
* [Bug network/22542] buffer overflow in sunrpc clnt_create
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
@ 2022-01-12  9:40 ` fweimer at redhat dot com
  2022-01-12  9:40 ` fweimer at redhat dot com
                   ` (7 subsequent siblings)
  8 siblings, 0 replies; 9+ messages in thread
From: fweimer at redhat dot com @ 2022-01-12  9:40 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Florian Weimer <fweimer at redhat dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
           See Also|                            |https://sourceware.org/bugz
                   |                            |illa/show_bug.cgi?id=28768

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
  2022-01-12  9:40 ` [Bug network/22542] buffer overflow in sunrpc clnt_create fweimer at redhat dot com
@ 2022-01-12  9:40 ` fweimer at redhat dot com
  2022-01-12 16:22 ` carnil at debian dot org
                   ` (6 subsequent siblings)
  8 siblings, 0 replies; 9+ messages in thread
From: fweimer at redhat dot com @ 2022-01-12  9:40 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Florian Weimer <fweimer at redhat dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |ASSIGNED
                 CC|                            |fweimer at redhat dot com
              Flags|                            |security+
           Assignee|unassigned at sourceware dot org   |fweimer at redhat dot com

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
  2022-01-12  9:40 ` [Bug network/22542] buffer overflow in sunrpc clnt_create fweimer at redhat dot com
  2022-01-12  9:40 ` fweimer at redhat dot com
@ 2022-01-12 16:22 ` carnil at debian dot org
  2022-01-14  8:14 ` [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219) siddhesh at sourceware dot org
                   ` (5 subsequent siblings)
  8 siblings, 0 replies; 9+ messages in thread
From: carnil at debian dot org @ 2022-01-12 16:22 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Salvatore Bonaccorso <carnil at debian dot org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |carnil at debian dot org

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219)
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
                   ` (2 preceding siblings ...)
  2022-01-12 16:22 ` carnil at debian dot org
@ 2022-01-14  8:14 ` siddhesh at sourceware dot org
  2022-01-14 21:21 ` sam at gentoo dot org
                   ` (4 subsequent siblings)
  8 siblings, 0 replies; 9+ messages in thread
From: siddhesh at sourceware dot org @ 2022-01-14  8:14 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Siddhesh Poyarekar <siddhesh at sourceware dot org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
              Alias|                            |CVE-2022-23219
            Summary|buffer overflow in sunrpc   |buffer overflow in sunrpc
                   |clnt_create                 |clnt_create
                   |                            |(CVE-2022-23219)
                 CC|                            |siddhesh at sourceware dot org

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219)
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
                   ` (3 preceding siblings ...)
  2022-01-14  8:14 ` [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219) siddhesh at sourceware dot org
@ 2022-01-14 21:21 ` sam at gentoo dot org
  2022-01-15 15:41 ` aurelien at aurel32 dot net
                   ` (3 subsequent siblings)
  8 siblings, 0 replies; 9+ messages in thread
From: sam at gentoo dot org @ 2022-01-14 21:21 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Sam James <sam at gentoo dot org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |sam at gentoo dot org

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219)
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
                   ` (4 preceding siblings ...)
  2022-01-14 21:21 ` sam at gentoo dot org
@ 2022-01-15 15:41 ` aurelien at aurel32 dot net
  2022-01-17  9:10 ` pgowda.cve at gmail dot com
                   ` (2 subsequent siblings)
  8 siblings, 0 replies; 9+ messages in thread
From: aurelien at aurel32 dot net @ 2022-01-15 15:41 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Aurelien Jarno <aurelien at aurel32 dot net> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |aurelien at aurel32 dot net

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219)
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
                   ` (5 preceding siblings ...)
  2022-01-15 15:41 ` aurelien at aurel32 dot net
@ 2022-01-17  9:10 ` pgowda.cve at gmail dot com
  2022-01-17 13:06 ` fweimer at redhat dot com
  2022-01-17 13:07 ` fweimer at redhat dot com
  8 siblings, 0 replies; 9+ messages in thread
From: pgowda.cve at gmail dot com @ 2022-01-17  9:10 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

pgowda <pgowda.cve at gmail dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |pgowda.cve at gmail dot com

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219)
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
                   ` (6 preceding siblings ...)
  2022-01-17  9:10 ` pgowda.cve at gmail dot com
@ 2022-01-17 13:06 ` fweimer at redhat dot com
  2022-01-17 13:07 ` fweimer at redhat dot com
  8 siblings, 0 replies; 9+ messages in thread
From: fweimer at redhat dot com @ 2022-01-17 13:06 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

--- Comment #2 from Florian Weimer <fweimer at redhat dot com> ---
Fixed for glibc 2.35 via:

commit 226b46770c82899b555986583294b049c6ec9b40
Author: Florian Weimer <fweimer@redhat.com>
Date:   Mon Jan 17 10:21:34 2022 +0100

    CVE-2022-23219: Buffer overflow in sunrpc clnt_create for "unix" (bug
22542)

    Processing an overlong pathname in the sunrpc clnt_create function
    results in a stack-based buffer overflow.

    Reviewed-by: Siddhesh Poyarekar <siddhesh@sourceware.org>

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219)
       [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
                   ` (7 preceding siblings ...)
  2022-01-17 13:06 ` fweimer at redhat dot com
@ 2022-01-17 13:07 ` fweimer at redhat dot com
  8 siblings, 0 replies; 9+ messages in thread
From: fweimer at redhat dot com @ 2022-01-17 13:07 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=22542

Florian Weimer <fweimer at redhat dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
   Target Milestone|---                         |2.35
         Resolution|---                         |FIXED
             Status|ASSIGNED                    |RESOLVED

--- Comment #3 from Florian Weimer <fweimer at redhat dot com> ---
.

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2022-01-17 13:07 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <bug-22542-131@http.sourceware.org/bugzilla/>
2022-01-12  9:40 ` [Bug network/22542] buffer overflow in sunrpc clnt_create fweimer at redhat dot com
2022-01-12  9:40 ` fweimer at redhat dot com
2022-01-12 16:22 ` carnil at debian dot org
2022-01-14  8:14 ` [Bug network/22542] buffer overflow in sunrpc clnt_create (CVE-2022-23219) siddhesh at sourceware dot org
2022-01-14 21:21 ` sam at gentoo dot org
2022-01-15 15:41 ` aurelien at aurel32 dot net
2022-01-17  9:10 ` pgowda.cve at gmail dot com
2022-01-17 13:06 ` fweimer at redhat dot com
2022-01-17 13:07 ` fweimer at redhat dot com

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).