zlib package in Ubuntu 14.04 LTS (Trusty) has not received patches for critical/high CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843

Bug #1729414 reported by Ryan Fisher
34
This bug affects 6 people
Affects Status Importance Assigned to Milestone
zlib (Ubuntu)
Confirmed
Low
Unassigned

Bug Description

The current package available to 14.04/trusty is 1:1.2.8.dfsg-1ubuntu1 which does not have the upstream fixes for the following CVEs:

* CVE-2016-9840 (high) (https://nvd.nist.gov/vuln/detail/CVE-2016-9840)
* CVE-2016-9841 (critical) (https://nvd.nist.gov/vuln/detail/CVE-2016-9841)
* CVE-2016-9842 (high) (https://nvd.nist.gov/vuln/detail/CVE-2016-9842)
* CVE-2016-9843 (critical) (https://nvd.nist.gov/vuln/detail/CVE-2016-9843)

Being that they are being categorized as such by NIST, it would be very nice to get these fixes backported to Trusty or the most recent version of zlib made available to Trusty.

Thanks!

Tags: trusty xenial
Ryan Fisher (techfish)
tags: added: trusty
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in zlib (Ubuntu):
status: New → Confirmed
Revision history for this message
Michael Leibowitz (michael-leibowitz) wrote :

This also appears to be the case in 16.04 LTS

tags: added: xenial
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

We have rated these vulnerabilities as being "low" priority as the undefined behaviour doesn't affect binaries built with gcc.

We will include them in a zlib security update if more important issues need to be addressed.

https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9840.html
https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9841.html
https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9842.html
https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9843.html

Changed in zlib (Ubuntu):
importance: Undecided → Low
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.