First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 280514
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Alex Legler <a3li@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 280514 depends on: 280648 Show dependency tree
Bug 280514 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2009-08-05 23:26 0000
From Secunia:
Some vulnerabilities have been reported in APR-util, which can potentially be
exploited to cause a DoS (Denial of Service) or compromise an application using
the library.

The vulnerabilities are caused due to integer overflow errors in the
"apr_rmm_malloc()", "apr_rmm_calloc()", and "apr_rmm_realloc()" functions in
misc/apr_rmm.c when aligning relocatable memory blocks, which can potentially
be exploited to cause buffer overflows.

------- Comment #1 From Alex Legler 2009-08-05 23:27:55 0000 -------
Patches at $URL, new releases are expected soon as well.

CC'ing infra.

------- Comment #2 From Arfrever Frehtes Taifersar Arahesis 2009-08-06 13:00:11 0000 -------
dev-libs/apr-1.3.8 and dev-libs/apr-util-1.3.9 are now in the tree.

------- Comment #3 From Arfrever Frehtes Taifersar Arahesis 2009-08-06 13:01:49 0000 -------
Please stabilize dev-libs/apr-1.3.8 and dev-libs/apr-util-1.3.9.

------- Comment #4 From Alex Legler 2009-08-06 13:02:47 0000 -------
Arches, please test and mark stable:
=dev-libs/apr-1.3.8
=dev-libs/apr-util-1.3.9
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"

Please note this is a high priority stabilization.

------- Comment #5 From Alex Legler 2009-08-06 13:30:36 0000 -------
amd64 stable.

Also tested successfully in my x86 chroot, but not marked stable in case anyone
from x86 wants to test themselves.

------- Comment #6 From Alex Legler 2009-08-06 13:47:19 0000 -------
GLSA draft filed.

------- Comment #7 From Markus Meier 2009-08-06 21:53:27 0000 -------
x86 stable

------- Comment #8 From Diego E. 'Flameeyes' Pettenò 2009-08-07 11:19:29 0000 -------
Uuuh has somebody tested this with the stable Apache? Double-checked and
rebuilt on my server but it fails to start (unable to bind the socket on port
80) with the new apr, works fine with 1.3.5…

------- Comment #9 From Diego E. 'Flameeyes' Pettenò 2009-08-07 12:11:45 0000 -------
Okay so this breaks badly on older kernels, like 2.6.26 which is widely used
for vservers.

Can we have more speed and less haste?

------- Comment #10 From Robert Buchholz 2009-08-07 12:58:48 0000 -------
removing arches, readding x86, you may want to drop stable again.

The patches in $URL should apply to 1.3.5 as well, so backporting seems a more
feasible approach to get it fixed timely.

------- Comment #11 From Diego E. 'Flameeyes' Pettenò 2009-08-07 13:06:40 0000 -------
amd64 as well (found the issue on that to begin with)

------- Comment #12 From Christian Faulhammer 2009-08-07 16:32:51 0000 -------
x86 reverted to testing.

------- Comment #13 From Robin Johnson 2009-08-07 20:45:24 0000 -------
Can somebody please backport?

------- Comment #14 From Stefan Behte 2009-08-08 02:45:54 0000 -------
FYI: Patches apply cleanly to apr-1.3.5 and apr-util-1.3.7.
Unfortunately I can't commit.

------- Comment #15 From Arfrever Frehtes Taifersar Arahesis 2009-08-10 03:34:09 0000 -------
I added "cloexec" USE flag for dev-libs/apr-1.3.8. Users, who want to build APR
on systems with newer kernels and use it on systems with older kernels, should
disable "cloexec" USE flag.

------- Comment #16 From Robert Buchholz 2009-08-10 11:44:58 0000 -------
Arches, please test and mark stable:
=dev-libs/apr-1.3.8
=dev-libs/apr-util-1.3.9
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"

------- Comment #17 From Tobias Klausmann 2009-08-10 15:59:00 0000 -------
Both stable on alpha.

------- Comment #18 From Markus Meier 2009-08-10 22:36:06 0000 -------
x86 stable

------- Comment #19 From Jeroen Roovers 2009-08-11 23:29:24 0000 -------
Stable for HPPA.

------- Comment #20 From Raúl Porcel 2009-08-14 13:54:20 0000 -------
arm/ia64/s390/sh/sparc stable 

------- Comment #21 From Alex Legler 2009-08-20 12:08:31 0000 -------
pcc, pcc64: ping!

------- Comment #22 From nixnut 2009-08-23 08:24:11 0000 -------
ppc stable

------- Comment #23 From Brent Baude 2009-08-24 14:55:17 0000 -------
ppc64 done

------- Comment #24 From Alex Legler 2009-08-24 20:29:53 0000 -------
GLSA already filed, pending 2 approvals.

------- Comment #25 From Alex Legler 2009-09-09 13:31:12 0000 -------
GLSA 200909-03, sorry for the delay.

First Last Prev Next    No search results available      Search page      Enter new bug