Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 584194 (CVE-2016-5104) - <app-pda/libimobiledevice-1.2.0-r1: Sockets listening on INADDR_ANY
Summary: <app-pda/libimobiledevice-1.2.0-r1: Sockets listening on INADDR_ANY
Status: RESOLVED FIXED
Alias: CVE-2016-5104
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-05-26 12:06 UTC by Agostino Sarubbo
Modified: 2018-07-03 00:40 UTC (History)
2 users (show)

See Also:
Package list:
app-pda/libimobiledevice-1.2.0-r1
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-05-26 12:06:15 UTC
From ${URL} :

It was found that libimobiledevice and libusbmuxd libraries accidentally bound a listening IPv4 TCP 
socket to INADDR_ANY instead of INADDR_LOOPBACK.

Upstream patches:

libusbmuxd: 
https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196

libimobiledevice: 
https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e

CVE request:

http://seclists.org/oss-sec/2016/q2/410


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Pacho Ramos gentoo-dev 2018-05-27 17:59:38 UTC
[master 8973207ac636] app-pda/libimobiledevice: Follow Fedora patches and GIT snapshot
 2 files changed, 116 insertions(+)
 create mode 100644 app-pda/libimobiledevice/libimobiledevice-1.2.0-r1.ebuild

this revision solves this
Comment 2 Agostino Sarubbo gentoo-dev 2018-06-28 08:02:58 UTC
amd64 stable
Comment 3 Larry the Git Cow gentoo-dev 2018-07-01 09:23:46 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f92be73ab349d2d9e8d63603b0225b4073bddb11

commit f92be73ab349d2d9e8d63603b0225b4073bddb11
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-07-01 09:13:55 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-07-01 09:13:55 +0000

    app-pda/libimobiledevice: stable 1.2.0-r1 for ppc, bug #584194
    
    Bug: https://bugs.gentoo.org/584194
    Package-Manager: Portage-2.3.41, Repoman-2.3.9
    RepoMan-Options: --include-arches="ppc"

 app-pda/libimobiledevice/libimobiledevice-1.2.0-r1.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2018-07-02 00:52:00 UTC
x86 stable
Comment 5 Pacho Ramos gentoo-dev 2018-07-02 18:57:38 UTC
old dropped
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2018-07-03 00:40:48 UTC
GLSA Vote: No