File _patchinfo of Package patchinfo.4786

<patchinfo incident="4786">
  <issue id="1041216" tracker="bnc">VUL-0: libmicrohttpd: multiple security issues fixed in 0.9.55</issue>
  <issue id="854443" tracker="bnc">VUL-0: CVE-2013-7038, CVE-2013-7039: libmicrohttpd: memory issues</issue>
  <issue id="2013-7038" tracker="cve" />
  <issue id="2013-7039" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>scarabeus_iv</packager>
  <description>
This update for libmicrohttpd fixes the following issues:

- CVE-2013-7038: The MHD_http_unescape function in libmicrohttpd might
  have allowed remote attackers to obtain sensitive information or cause
  a denial of service (crash) via unspecified vectors that trigger an
  out-of-bounds read. (bsc#854443)
- CVE-2013-7039: Stack-based buffer overflow in the MHD_digest_auth_check
  function in libmicrohttpd, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is
  set to a large value, allowed remote attackers to cause a denial of
  service (crash) or possibly execute arbitrary code via a long URI in an
  authentication header. (bsc#854443)

- Fixed various bugs found during a 2017 audit, which are more hardening
  measures and not security issues. (bsc#1041216)

</description>
  <summary>Security update for libmicrohttpd</summary>
</patchinfo>
openSUSE Build Service is sponsored by