File _patchinfo of Package patchinfo.4786
<patchinfo incident="4786">
<issue id="1041216" tracker="bnc">VUL-0: libmicrohttpd: multiple security issues fixed in 0.9.55</issue>
<issue id="854443" tracker="bnc">VUL-0: CVE-2013-7038, CVE-2013-7039: libmicrohttpd: memory issues</issue>
<issue id="2013-7038" tracker="cve" />
<issue id="2013-7039" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>scarabeus_iv</packager>
<description>
This update for libmicrohttpd fixes the following issues:
- CVE-2013-7038: The MHD_http_unescape function in libmicrohttpd might
have allowed remote attackers to obtain sensitive information or cause
a denial of service (crash) via unspecified vectors that trigger an
out-of-bounds read. (bsc#854443)
- CVE-2013-7039: Stack-based buffer overflow in the MHD_digest_auth_check
function in libmicrohttpd, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is
set to a large value, allowed remote attackers to cause a denial of
service (crash) or possibly execute arbitrary code via a long URI in an
authentication header. (bsc#854443)
- Fixed various bugs found during a 2017 audit, which are more hardening
measures and not security issues. (bsc#1041216)
</description>
<summary>Security update for libmicrohttpd</summary>
</patchinfo>