Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 533736 - <net-misc/miniupnpd-1.10_pre20141209: multiple vulnerabilities
Summary: <net-misc/miniupnpd-1.10_pre20141209: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-28 09:22 UTC by Agostino Sarubbo
Modified: 2015-03-03 14:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-12-28 09:22:49 UTC
From ${URL} :

Besides that, I found a few memory corruption vulnerabilities in the code.
 
Fixes:
 
https://github.com/miniupnp/miniupnp/commit/d00b75782e7d73e78d0b935cee6f4873bc48c9e8
https://github.com/miniupnp/miniupnp/commit/7c91c4e933e96b913b72685d093126d282b87db6

Some memory corruption fix:

https://github.com/miniupnp/miniupnp/commit/e6bc04aa06341fa4df3ccae87a167e9adf816911

A buffer overrun in ParseHttpHeaders() fix:

https://github.com/miniupnp/miniupnp/commit/dd39ecaa935a9c23176416b38a3b80d577f21048

Added check if BuildHeader_upnphttp() failed to allocate memory:

https://github.com/miniupnp/miniupnp/commit/ec94c5663fe80dd6ceea895c73e2be66b1ef6bf4



@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Bjarke Istrup Pedersen (RETIRED) gentoo-dev 2014-12-28 16:29:55 UTC
I have bumped it to 1.10_pre20141209 - thanks :)
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-12-31 14:43:11 UTC
Maintainer(s), Thank you for your work. 

No GLSA needed as there are no stable versions.

Leaving Open for CVE assignment (Already requested in URL)
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2015-03-03 14:44:46 UTC
Will add CVE later, tracking externally.