Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 585278 (CVE-2016-5301) - <net-libs/libtorrent-rasterbar-1.0.9-r2: Crash while parsing invalid chunked HTTP or UPnP response
Summary: <net-libs/libtorrent-rasterbar-1.0.9-r2: Crash while parsing invalid chunked ...
Status: RESOLVED FIXED
Alias: CVE-2016-5301
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on: 530720 rb_libtorrent-1.0
Blocks:
  Show dependency tree
 
Reported: 2016-06-07 12:00 UTC by Agostino Sarubbo
Modified: 2017-05-26 23:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-06-07 12:00:31 UTC
From ${URL} :

A vulnerability was found in libtorrent. A specially crafted HTTP response from a tracker (or 
potentially a UPnP broadcast) can crash libtorrent in the parse_chunk_header() function.


Upstream bug:

https://github.com/arvidn/libtorrent/issues/780

Upstream fix:

https://github.com/arvidn/libtorrent/pull/782


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Davide Pesavento gentoo-dev 2016-08-18 20:45:07 UTC
1.0.9-r2 contains the backported patch. However it cannot be stabilized yet due to bug 547062.
Comment 2 Andreas Sturmlechner gentoo-dev 2017-03-18 23:08:58 UTC
Affected versions removed in a23ccc8f8406ca9a136093270db9523465f75bd4
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2017-04-30 19:10:56 UTC
GLSA Vote: No

Maintainer(s), please drop the vulnerable version(s).
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2017-05-26 23:35:14 UTC
Thank you for cleanup.
Thank you all for you work. 
Closing as [noglsa].