Vulnerability Description
The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Librest | 0.7.92 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2015-2237.htmlThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2015/03/23/8Mailing ListThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=742644Issue TrackingThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1183982Issue TrackingThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1199049Issue TrackingPatchThird Party Advisory
- https://git.gnome.org/browse/librest/commit/?id=b50ace7738ea03817acdad87fb2b338aPatchThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2237.htmlThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2015/03/23/8Mailing ListThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=742644Issue TrackingThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1183982Issue TrackingThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1199049Issue TrackingPatchThird Party Advisory
- https://git.gnome.org/browse/librest/commit/?id=b50ace7738ea03817acdad87fb2b338aPatchThird Party Advisory
FAQ
What is CVE-2015-2675?
CVE-2015-2675 is a vulnerability with a CVSS score of 7.5 (HIGH). The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (applic...
How severe is CVE-2015-2675?
CVE-2015-2675 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2675?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Librest.