Overview

Request 631973 accepted

- Added CVE-2018-14779.patch: Fixed an buffer overflow and an out of bounds
memory read in ykpiv_transfer_data(), which could be triggered by a malicious
token. (CVE-2018-14779, bsc#1104809, YSA-2018-03)
- Added CVE-2018-14780.patch: Fixed an buffer overflow and an out of bounds
memory read in _ykpiv_fetch_object(), which could be triggered by a malicious
token. (CVE-2018-14780, bsc#1104811, YSA-2018-03)


Leap Reviewbot's avatar

home:kbabioch:branches:openSUSE:Leap:42.3:Update/yubico-piv-tool@a62c5c510b0030c2bb3052f61b418282 -> openSUSE:Leap:42.3:Update/yubico-piv-tool

expected origin is 'openSUSE:Leap:42.2' (changed)


Leap Reviewbot's avatar

home:kbabioch:branches:openSUSE:Leap:42.3:Update/yubico-piv-tool@df07739824407a73444cc1889b7ebdba -> openSUSE:Leap:42.3:Update/yubico-piv-tool

expected origin is 'openSUSE:Leap:42.2' (changed)

Request History
Karol Babioch's avatar

kbabioch created request

- Added CVE-2018-14779.patch: Fixed an buffer overflow and an out of bounds
memory read in ykpiv_transfer_data(), which could be triggered by a malicious
token. (CVE-2018-14779, bsc#1104809, YSA-2018-03)
- Added CVE-2018-14780.patch: Fixed an buffer overflow and an out of bounds
memory read in _ykpiv_fetch_object(), which could be triggered by a malicious
token. (CVE-2018-14780, bsc#1104811, YSA-2018-03)


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Saul Goodman's avatar

licensedigger accepted review

ok


Maintenance Bot's avatar

maintbot added yubico-piv-tool as a reviewer

Submission for yubico-piv-tool by someone who is not maintainer in the devel project (security). Please review


Maintenance Bot's avatar

maintbot accepted review

ok


Torsten Gruner's avatar

Simmphonie accepted review

ok


Torsten Gruner's avatar

Simmphonie approved review

ok


Karol Babioch's avatar

kbabioch moved maintenance target to openSUSE:Maintenance:8675


Karol Babioch's avatar

kbabioch accepted request

accepted request 631973:Thanks!

For information about the update, see https://build.opensuse.org/project/maintenance_incidents/openSUSE:Maintenance

openSUSE Build Service is sponsored by