Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 628186 - <media-tv/kodi-18.0: multiple vulnerabilities through embedded UnRAR version (CVE-2017-{12940-12942})
Summary: <media-tv/kodi-18.0: multiple vulnerabilities through embedded UnRAR version ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [noglsa cve]
Keywords:
Depends on: 682558
Blocks: CVE-2017-12940, CVE-2017-12941, CVE-2017-12942
  Show dependency tree
 
Reported: 2017-08-18 14:57 UTC by GLSAMaker/CVETool Bot
Modified: 2019-10-26 14:17 UTC (History)
3 users (show)

See Also:
Package list:
=media-tv/kodi-18.1
Runtime testing required: Yes


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-08-18 14:57:19 UTC
CVE-2017-12940 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12940):
  libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the
  EncodeFileName::Decode call within the Archive::ReadHeader15 function.

CVE-2017-12941 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12941):
  libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the
  Unpack::Unpack20 function.

CVE-2017-12942 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12942):
  libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ
  function.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-08-18 15:02:00 UTC
See tracker bug 628178 for more details.
Comment 2 Craig Andrews gentoo-dev 2017-08-18 16:08:00 UTC
Reported upstream at:
https://github.com/notspiff/vfs.rar/issues/14
https://trac.kodi.tv/ticket/17575
Comment 3 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-09-12 01:47:48 UTC
From Upstream's response

>Note that this vulnerability doesn't impact Kodi 18 (or later) because unrar has
>been moved to an addon (that addon is impacted, issue reported at ​
>https://github.com/notspiff/vfs.rar/issues/14 )

Gentoo Security Padawan
ChrisADR
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2018-11-27 22:38:32 UTC
Whoa a year later and 18 is still pre-release.
Comment 5 Aaron Bauman (RETIRED) gentoo-dev 2019-03-24 01:36:23 UTC
@maintainer, please let us know when you are ready to stabilize >=18.0
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2019-04-04 22:44:30 UTC
@arches, please stabilize.
Comment 7 Stabilization helper bot gentoo-dev 2019-04-04 23:01:35 UTC
An automated check of this bug failed - repoman reported dependency errors (77 lines truncated): 

> dependency.bad media-tv/kodi/kodi-18.1.ebuild: DEPEND: amd64(default/linux/amd64/17.0) ['>=media-video/ffmpeg-4.0.3:=[encode,postproc]', 'media-video/ffmpeg[libressl,-openssl]', 'media-video/ffmpeg[-libressl,openssl]']
> dependency.bad media-tv/kodi/kodi-18.1.ebuild: RDEPEND: amd64(default/linux/amd64/17.0) ['>=media-video/ffmpeg-4.0.3:=[encode,postproc]', 'media-video/ffmpeg[libressl,-openssl]', 'media-video/ffmpeg[-libressl,openssl]']
> dependency.bad media-tv/kodi/kodi-18.1.ebuild: DEPEND: amd64(default/linux/amd64/17.0/desktop) ['>=media-video/ffmpeg-4.0.3:=[encode,postproc]', 'media-video/ffmpeg[libressl,-openssl]', 'media-video/ffmpeg[-libressl,openssl]']
Comment 8 mercuriete 2019-05-19 15:31:02 UTC
glsa-check --test all is not working properly


~ $ glsa-check --test all
This system is not affected by any of the listed GLSAs


My version of kodi is: media-tv/kodi-17.6-r11


glsa test is checking a bad version: https://security.gentoo.org/glsa/201710-21

Unaffected versions	>= 17.3-r1


But this is not true because upstream said:

https://trac.kodi.tv/ticket/17575

Resolution set to Won't be fixed/added
Status changed from new to closed
Kodi 17 is end of life.

In v18 UnRAR isn't part of Kodi anymore.



So please fix glsa checks to be >= 18.0
Comment 9 Frank Krömmelbein 2019-08-08 11:09:48 UTC
I think stabilization should continue now, since a month ago ffmpeg 4.1.3 was stabilized for x86, the last relevant Arch for kodi.
Furthermore I would suggest to stabilize the latest version of kodi 18.3-r1.
Comment 10 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-26 14:17:39 UTC
GLSA Vote: No!

Repository is clean, all done!