summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Sebastian Harl [Thu, 28 Jul 2016 20:25:08 +0000 (21:25 +0100)]
collectd (5.4.1-6+deb8u1) jessie-security; urgency=high
* debian/patches/CVE-2016-6254.dpatch: Fix heap overflow in the network
plugin. Emilien Gaspar has identified a heap overflow in parse_packet(),
the function used by the network plugin to parse incoming network packets.
Thanks to Florian Forster for reporting the bug in Debian.
(Closes: #832507, CVE-2016-6254)
* debian/patches/bts832577-gcry-control.dpatch: Fix improper usage of
gcry_control. A team of security researchers at Columbia University and
the University of Virginia discovered that GCrypt's gcry_control is
sometimes called without checking its return value for an error. This may
cause the program to be initialized without the desired, secure settings.
(Closes: #832577)
[dgit import package collectd 5.4.1-6+deb8u1]
Sebastian Harl [Tue, 28 Jan 2014 20:47:00 +0000 (20:47 +0000)]
Import collectd_5.4.1.orig.tar.gz
[dgit import orig collectd_5.4.1.orig.tar.gz]