View | Details | Raw Unified | Return to bug 208840
Collapse All | Expand All

(-)security/vuxml/vuln.xml (+36 lines)
Lines 58-63 Link Here
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="6ec9f210-0404-11e6-9aee-bc5ff4fb5ea1">
62
    <topic>dhcpcd -- multiple vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>dhcpcd</name>
66
	<range><lt>6.10.2</lt></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p>Jüri Aedla reports:</p>
72
	<blockquote cite="https://android.googlesource.com/platform/external/dhcpcd/+/73c09dd8067250734511d955d8f792b41c7213f0">
73
	  <p>[CVE-2014-7912] The get_option function in dhcp.c in dhcpcd before 6.2.0, as used
74
	    in dhcpcd 5.x in Android before 5.1 and other products, does not validate the
75
	    relationship between length fields and the amount of data, which allows remote
76
	    DHCP servers to execute arbitrary code or cause a denial of service (memory
77
	    corruption) via a large length value of an option in a DHCPACK message.</p>
78
	  <p>CVE-2014-7913] The print_option function in dhcp-common.c in dhcpcd through 6.9.1,
79
	    as used in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products,
80
	    misinterprets the return value of the snprintf function, which allows remote
81
	    DHCP servers to execute arbitrary code or cause a denial of service (memory
82
	    corruption) via a crafted message.</p>
83
	</blockquote>
84
      </body>
85
    </description>
86
    <references>
87
      <cvename>CVE-2014-7912</cvename>
88
      <cvename>CVE-2014-7913</cvename>
89
      <url>http://roy.marples.name/projects/dhcpcd/info/528541c4c619520e</url>
90
    </references>
91
    <dates>
92
      <discovery>2014-11-13</discovery>
93
      <entry>2016-04-16</entry>
94
    </dates>
95
  </vuln>
96
61
  <vuln vid="e21474c6-031a-11e6-aa86-001999f8d30b">
97
  <vuln vid="e21474c6-031a-11e6-aa86-001999f8d30b">
62
    <topic>PJSIP -- TCP denial of service in PJProject</topic>
98
    <topic>PJSIP -- TCP denial of service in PJProject</topic>
63
    <affects>
99
    <affects>

Return to bug 208840