Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 627224 - <sci-libs/gdal-2.3.0: Heap-buffer-overflow in NITFRasterBand::IReadBlock
Summary: <sci-libs/gdal-2.3.0: Heap-buffer-overflow in NITFRasterBand::IReadBlock
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugs.chromium.org/p/oss-fuzz/...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 663462
Blocks:
  Show dependency tree
 
Reported: 2017-08-07 07:47 UTC by Agostino Sarubbo
Modified: 2018-08-15 08:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-08-07 07:47:13 UTC
OSS-Fuzz is a Continuous Fuzzing for Open Source Software. See $URL for more details about the issue.
Commit fix: https://trac.osgeo.org/gdal/changeset/39498



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Amy Liffey gentoo-dev 2018-08-12 12:53:02 UTC
Fixed in 2.3.0 [1].

[1] https://github.com/OSGeo/gdal/blob/v2.3.0/gdal/frmts/nitf/nitfdataset.cpp#L573
Comment 2 Larry the Git Cow gentoo-dev 2018-08-15 08:14:40 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8a11d4f138645601f3bcf3475bd18577681b3928

commit 8a11d4f138645601f3bcf3475bd18577681b3928
Author:     Amy Liffey <amynka@gentoo.org>
AuthorDate: 2018-08-15 08:12:19 +0000
Commit:     Amy Liffey <amynka@gentoo.org>
CommitDate: 2018-08-15 08:12:19 +0000

    sci-libs/gdal: remove old affected version
    
    Bug: https://bugs.gentoo.org/621712
    Bug: https://bugs.gentoo.org/621716
    Bug: https://bugs.gentoo.org/621718
    Bug: https://bugs.gentoo.org/622202
    Bug: https://bugs.gentoo.org/623028
    Bug: https://bugs.gentoo.org/627224
    Bug: https://bugs.gentoo.org/621714
    Bug: https://bugs.gentoo.org/621720
    Closes: https://bugs.gentoo.org/663462
    Package-Manager: Portage-2.3.40, Repoman-2.3.9

 sci-libs/gdal/Manifest             |   1 -
 sci-libs/gdal/gdal-2.2.3-r1.ebuild | 289 -------------------------------------
 2 files changed, 290 deletions(-)
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-08-15 08:32:57 UTC
GLSA vote: No.