Gentoo Archives: gentoo-commits

From: "Tobias Heinlein (keytoaster)" <keytoaster@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] gentoo commit in xml/htdocs/security/en/glsa: glsa-201402-08.xml
Date: Fri, 07 Feb 2014 09:48:08
Message-Id: 20140207094804.816B22004C@flycatcher.gentoo.org
1 keytoaster 14/02/07 09:48:04
2
3 Modified: glsa-201402-08.xml
4 Log:
5 Rewritten advisory, since the OpenSSL vulnerabilities only affect Windows builds.
6
7 Revision Changes Path
8 1.3 xml/htdocs/security/en/glsa/glsa-201402-08.xml
9
10 file : http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201402-08.xml?rev=1.3&view=markup
11 plain: http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201402-08.xml?rev=1.3&content-type=text/plain
12 diff : http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201402-08.xml?r1=1.2&r2=1.3
13
14 Index: glsa-201402-08.xml
15 ===================================================================
16 RCS file: /var/cvsroot/gentoo/xml/htdocs/security/en/glsa/glsa-201402-08.xml,v
17 retrieving revision 1.2
18 retrieving revision 1.3
19 diff -u -r1.2 -r1.3
20 --- glsa-201402-08.xml 6 Feb 2014 16:54:43 -0000 1.2
21 +++ glsa-201402-08.xml 7 Feb 2014 09:48:04 -0000 1.3
22 @@ -3,13 +3,13 @@
23 <?xml-stylesheet href="/xsl/guide.xsl" type="text/xsl"?>
24 <!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
25 <glsa id="201402-08">
26 - <title>stunnel: Multiple vulnerabilities</title>
27 - <synopsis>Multiple vulnerabilities have been found in stunnel, the worst of
28 - which may cause a Denial of Service condition.
29 + <title>stunnel: Arbitrary code execution</title>
30 + <synopsis>A vulnerability has been found in stunnel, allowing for the
31 + execution of arbitrary code.
32 </synopsis>
33 <product type="ebuild">stunnel</product>
34 <announced>February 06, 2014</announced>
35 - <revised>February 06, 2014: 2</revised>
36 + <revised>February 07, 2014: 4</revised>
37 <bug>460278</bug>
38 <access>remote</access>
39 <affected>
40 @@ -25,13 +25,15 @@
41 </p>
42 </background>
43 <description>
44 - <p>Multiple vulnerabilities have been discovered in stunnel. Please review
45 - the CVE identifiers referenced below for details.
46 + <p>A buffer overflow vulnerability has been discovered in stunnel. Please
47 + review the CVE identifier referenced below for details.
48 </p>
49 </description>
50 <impact type="normal">
51 - <p>A remote attacker could cause a Denial of Service condition or disclose
52 - potentially sensitive information.
53 + <p>A remote attacker could entice a user to connect to a malicious proxy
54 + server, resulting in the execution of arbitrary code within the
55 + configured chroot directory, with the privileges of the user running
56 + stunnel. Please review the references below for details.
57 </p>
58 </impact>
59 <workaround>
60 @@ -47,15 +49,15 @@
61
62 </resolution>
63 <references>
64 - <uri link="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2686">CVE-2012-2686</uri>
65 - <uri link="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0166">CVE-2013-0166</uri>
66 - <uri link="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0169">CVE-2013-0169</uri>
67 <uri link="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1762">CVE-2013-1762</uri>
68 + <uri link="https://www.stunnel.org/CVE-2013-1762.html">stunnel:
69 + CVE-2013-1762
70 + </uri>
71 </references>
72 <metadata tag="requester" timestamp="Fri, 23 Aug 2013 14:54:34 +0000">
73 creffett
74 </metadata>
75 - <metadata tag="submitter" timestamp="Thu, 06 Feb 2014 16:48:06 +0000">
76 + <metadata tag="submitter" timestamp="Fri, 07 Feb 2014 09:46:24 +0000">
77 pinkbyte
78 </metadata>
79 </glsa>