Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 587572 (CVE-2016-5823) - <dev-libs/libical-3.0.0: Segmentation fault on crafted file
Summary: <dev-libs/libical-3.0.0: Segmentation fault on crafted file
Status: RESOLVED FIXED
Alias: CVE-2016-5823
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on: 671576 674700
Blocks: CVE-2016-5824
  Show dependency tree
 
Reported: 2016-06-30 09:20 UTC by Agostino Sarubbo
Modified: 2019-04-02 04:18 UTC (History)
2 users (show)

See Also:
Package list:
dev-libs/libical-3.0.4
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-06-30 09:20:25 UTC
From ${URL} :

A segmentation fault triggered by processing crafted files was found in libical 0.47 and libical 1.0.

Upstream bug (not yet public):

https://bugzilla.mozilla.org/show_bug.cgi?id=1275400

CVE assignment:

http://seclists.org/oss-sec/2016/q2/604


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Pacho Ramos gentoo-dev 2017-06-04 18:44:10 UTC
we have 2.0.x in the tree... but I don't know if it fixes this
Comment 2 Andreas Sturmlechner gentoo-dev 2019-01-18 10:32:59 UTC
Arches, please stabilise.
Comment 3 Rolf Eike Beer archtester 2019-01-20 18:57:45 UTC
sparc stable
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2019-01-21 23:39:02 UTC
ia64 stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2019-01-21 23:39:55 UTC
ppc stable
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2019-01-21 23:40:42 UTC
ppc64 stable
Comment 7 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-01-22 08:39:35 UTC
amd64 stable
Comment 8 Thomas Deutschmann (RETIRED) gentoo-dev 2019-01-24 22:25:05 UTC
x86 stable
Comment 9 Markus Meier gentoo-dev 2019-01-31 20:19:28 UTC
arm stable
Comment 10 Andreas Sturmlechner gentoo-dev 2019-03-28 21:34:17 UTC
ping alpha.
Comment 11 Larry the Git Cow gentoo-dev 2019-03-29 09:25:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=498a9648290b3e85b8e04d22c2a91e8afeb0c7b0

commit 498a9648290b3e85b8e04d22c2a91e8afeb0c7b0
Author:     Tobias Klausmann <klausman@gentoo.org>
AuthorDate: 2019-03-29 09:25:18 +0000
Commit:     Tobias Klausmann <klausman@gentoo.org>
CommitDate: 2019-03-29 09:25:33 +0000

    dev-libs/libical-3.0.4-r0: alpha stable
    
    Bug: http://bugs.gentoo.org/587572
    Signed-off-by: Tobias Klausmann <klausman@gentoo.org>

 dev-libs/libical/libical-3.0.4.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 12 Aaron Bauman (RETIRED) gentoo-dev 2019-03-29 18:16:21 UTC
@maintainer, please drop vulnerable.
Comment 13 Larry the Git Cow gentoo-dev 2019-03-30 09:59:46 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b8998a9bbdb89e01d0e0d5bb722ff7b5705f46d6

commit b8998a9bbdb89e01d0e0d5bb722ff7b5705f46d6
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2019-03-29 21:14:40 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2019-03-30 09:58:22 +0000

    dev-libs/libical: Drop vulnerable 2.0.0-r3
    
    Bug: https://bugs.gentoo.org/587572
    Package-Manager: Portage-2.3.62, Repoman-2.3.12
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 dev-libs/libical/Manifest                          |  1 -
 ...ical-2.0.0-libical.pc-fix-libdir-location.patch | 28 ----------
 ...cal-2.0.0-libical.pc-icu-move-to-requires.patch | 47 -----------------
 ...al-2.0.0-libical.pc-icu-remove-full-paths.patch | 44 ----------------
 ...libical-2.0.0-libical.pc-set-full-version.patch | 19 -------
 dev-libs/libical/files/libical-2.0.0-tests.patch   | 38 --------------
 dev-libs/libical/libical-2.0.0-r3.ebuild           | 60 ----------------------
 7 files changed, 237 deletions(-)
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2019-04-02 04:18:38 UTC
This issue was resolved and addressed in
 GLSA 201904-02 at https://security.gentoo.org/glsa/201904-02
by GLSA coordinator Aaron Bauman (b-man).