Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 628084 (CVE-2017-7555) - <app-admin/augeas-1.8.1: parse_name() mishandles crafted strings (CVE-2017-7555)
Summary: <app-admin/augeas-1.8.1: parse_name() mishandles crafted strings (CVE-2017-7555)
Status: RESOLVED FIXED
Alias: CVE-2017-7555
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://seclists.org/oss-sec/2017/q3/309
Whiteboard: C3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-17 08:13 UTC by Aleksandr Wagner (Kivak)
Modified: 2017-12-20 21:57 UTC (History)
1 user (show)

See Also:
Package list:
=app-admin/augeas-1.8.1 alpha amd64 hppa ia64 ppc sparc x86
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-08-17 08:13:06 UTC
From $URL:

A vulnerability was found in augeas <http://augeas.net/> that could
allow attackers to cause memory corruption possibly leading to arbitrary
code execution by passing crafted strings that would be mis-handled by
parse_name().  A patch created by David Lutterkort is available on the
following PR:

https://github.com/hercules-team/augeas/pull/480

Briefly, input strings ending with a whitespace char would be escaped
(aug_escape_name) then incorrectly trimmed in parse_name, leading to a
later loop stepping over the terminating NUL character.  Crashes in
libvirtd were observed.

This issue was discovered by Han Han (Red Hat) through fuzzing with the
Dice testing framework.

https://bugzilla.redhat.com/show_bug.cgi?id=1478373

-- 
Doran Moppert
Red Hat Product Security
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2017-08-17 23:14:13 UTC
1.7.0-r1 and/or 1.8.0-r1 should be fast stablized (both have the patch).  Older versions removed.
Comment 2 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-09-01 00:08:54 UTC
(In reply to Matthew Thode ( prometheanfire ) from comment #1)
> 1.7.0-r1 and/or 1.8.0-r1 should be fast stablized (both have the patch). 
> Older versions removed.

Thank you Matthew, please call for stabilization when necessary or let us know.

Gentoo Security Padawan
ChrisADR
Comment 3 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2017-09-01 00:54:20 UTC
please stablize the following

=app-admin/augeas-1.8.1 alpha amd64 hppa ia64 ppc sparc x86
Comment 4 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-09-01 01:08:52 UTC
@Arches please test and mark stable.

Gentoo Security Padawan
ChrisADR
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2017-09-01 22:21:23 UTC
ia64 stable
Comment 6 Tobias Klausmann (RETIRED) gentoo-dev 2017-09-04 07:34:35 UTC
Stable on alpha.
Comment 7 Aaron Bauman (RETIRED) gentoo-dev 2017-09-04 22:20:00 UTC
amd64/x86 stable
Comment 8 Aaron Bauman (RETIRED) gentoo-dev 2017-09-10 22:19:19 UTC
sparc was dropped to exp.

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b5901d8f716555a1479f12313a2925fcadd177a9
Comment 9 Sergei Trofimovich (RETIRED) gentoo-dev 2017-09-24 19:58:37 UTC
ppc stable
Comment 10 Sergei Trofimovich (RETIRED) gentoo-dev 2017-10-14 11:01:59 UTC
hppa stable
Comment 11 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-10-14 12:58:28 UTC
Thank you all.

@Maintainers please clean the tree.

@Security please vote
Comment 12 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2017-10-14 19:34:10 UTC
cleaned up
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2017-10-14 23:09:43 UTC
GLSA Vote: No