Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 546414 - <dev-libs/nettle-3.1.1: out-of-bounds reads in memxor
Summary: <dev-libs/nettle-3.1.1: out-of-bounds reads in memxor
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 560724
Blocks:
  Show dependency tree
 
Reported: 2015-04-13 08:11 UTC by Agostino Sarubbo
Modified: 2016-06-21 09:30 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-04-13 08:11:10 UTC
From ${URL} :

From Nettle 3.1 ChangeLog:

> NEWS for the Nettle 3.1 release
> [...]
>   Bug fixes:
> [...]
>   * Eliminate out-of-bounds reads in the C implementation of
>     memxor (related to valgrind's --partial-loads-ok flag).

This refers to the following commits:

(branch merge)
https://git.lysator.liu.se/nettle/nettle/commit/20525ae7096438f9816dc1faffe9b9d8984bb0a7 

and specifically:
https://git.lysator.liu.se/nettle/nettle/commit/57122465ccc89996f9f8f71e7607ee67a2860e1c
https://git.lysator.liu.se/nettle/nettle/commit/842abf376289059cd3dce34a851a3f701ad1f9b3

No further information is available at this moment.
Comment 1


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Alon Bar-Lev (RETIRED) gentoo-dev 2015-04-13 09:35:05 UTC
It will take much time for 3.1 to become stable, we will have to back port this if it effects 2.7
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2015-04-19 15:47:17 UTC
Since back porting is needed, setting Whiteboard to ebuild.
Comment 3 Alon Bar-Lev (RETIRED) gentoo-dev 2015-04-19 18:41:11 UTC
it is not trivial backport, are there any references that someone has else already done this?
Comment 4 Hanno Böck gentoo-dev 2016-02-02 15:10:49 UTC
This looks outdated, nettle 3.1.1 is currently the only version in the tree.
Comment 5 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-02-03 13:50:52 UTC
(In reply to Hanno Boeck from comment #4)
> This looks outdated, nettle 3.1.1 is currently the only version in the tree.

Thanks for picking up on this, indeed nettle 3.1.1 got stabilized in bug 560724

@Security:
GLSA Vote: No

Fwiw, redhad concludes "This does not appear to have any security relevance on our target architectures. If anybody has any evidence to the contrary, please feel free to reopen the bug."

Anyone aware of any CVE for this issue that can document a contrary view, or a statement where one is not assigned for reason of no security implication?