CVE-2013-2131
Publication date 4 January 2015
Last updated 24 July 2024
Ubuntu priority
Description
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rrdtool | 25.10 questing |
Fixed 1.7.2-3ubuntu5
|
| 25.04 plucky |
Fixed 1.7.2-3ubuntu5
|
|
| 24.04 LTS noble |
Fixed 1.7.2-3ubuntu5
|
|
| 22.04 LTS jammy |
Fixed 1.7.2-3ubuntu5
|
|
| 20.04 LTS focal |
Fixed 1.7.2-3build1
|
|
| 18.04 LTS bionic |
Fixed 1.7.0-1build1
|
|
| 16.04 LTS xenial |
Fixed 1.4.8-1
|
|
| 14.04 LTS trusty |
Vulnerable
|
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
rodrigo-zaiden
xenial was patched in release version 1.4.8-1, and later it was upgraded to the new upstream version 1.5 that already has the fix (no need to add an explict patch). Since then, every Ubuntu release already has the fix applied.