Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 621716 - <sci-libs/gdal-2.3.0: Index-out-of-bounds in CPLErrorSetState
Summary: <sci-libs/gdal-2.3.0: Index-out-of-bounds in CPLErrorSetState
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugs.chromium.org/p/oss-fuzz/...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 621712
Blocks:
  Show dependency tree
 
Reported: 2017-06-14 07:05 UTC by Agostino Sarubbo
Modified: 2018-08-15 08:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-06-14 07:05:07 UTC
OSS-Fuzz is a Continuous Fuzzing for Open Source Software. See $URL for more details about the issue.
Commit fix: https://trac.osgeo.org/gdal/changeset/38236



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Amy Liffey gentoo-dev 2018-08-11 19:07:04 UTC
Already fixed at 2.3.0 [1].

[1] https://github.com/OSGeo/gdal/blob/v2.3.0/gdal/port/cpl_error.cpp#L775
Comment 2 Larry the Git Cow gentoo-dev 2018-08-15 08:14:45 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8a11d4f138645601f3bcf3475bd18577681b3928

commit 8a11d4f138645601f3bcf3475bd18577681b3928
Author:     Amy Liffey <amynka@gentoo.org>
AuthorDate: 2018-08-15 08:12:19 +0000
Commit:     Amy Liffey <amynka@gentoo.org>
CommitDate: 2018-08-15 08:12:19 +0000

    sci-libs/gdal: remove old affected version
    
    Bug: https://bugs.gentoo.org/621712
    Bug: https://bugs.gentoo.org/621716
    Bug: https://bugs.gentoo.org/621718
    Bug: https://bugs.gentoo.org/622202
    Bug: https://bugs.gentoo.org/623028
    Bug: https://bugs.gentoo.org/627224
    Bug: https://bugs.gentoo.org/621714
    Bug: https://bugs.gentoo.org/621720
    Closes: https://bugs.gentoo.org/663462
    Package-Manager: Portage-2.3.40, Repoman-2.3.9

 sci-libs/gdal/Manifest             |   1 -
 sci-libs/gdal/gdal-2.2.3-r1.ebuild | 289 -------------------------------------
 2 files changed, 290 deletions(-)
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-08-15 08:32:04 UTC
GLSA vote: No.