Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 633826 (CVE-2017-14608) - <media-libs/libraw-0.18.7: Out-of-bounds read in the kodak_65000_load_raw function
Summary: <media-libs/libraw-0.18.7: Out-of-bounds read in the kodak_65000_load_raw fun...
Status: RESOLVED FIXED
Alias: CVE-2017-14608
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-09 09:17 UTC by Agostino Sarubbo
Modified: 2018-11-24 22:26 UTC (History)
1 user (show)

See Also:
Package list:
=media-libs/libraw-0.18.8
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-10-09 09:17:27 UTC
From ${URL} :

In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to 
cause an application crash.

Upstream issue:

https://github.com/LibRaw/LibRaw/issues/101

Upstream patch:

https://github.com/LibRaw/LibRaw/commit/d13e8f6d1e987b7491182040a188c16a395f1d21


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2018-03-25 15:51:16 UTC
0.18.7 has the fix, but targeting a newer version.

@arches, please stabilize.
Comment 2 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-25 20:33:23 UTC
ppc64 stable
Comment 3 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-25 21:00:03 UTC
ppc stable
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-25 21:58:44 UTC
ia64 stable
Comment 5 Larry the Git Cow gentoo-dev 2018-03-29 02:01:13 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1980bbc7d65aa157559932a238a11731a1fb2dd5

commit 1980bbc7d65aa157559932a238a11731a1fb2dd5
Author:     Aaron Bauman <bman@gentoo.org>
AuthorDate: 2018-03-29 01:59:01 +0000
Commit:     Aaron Bauman <bman@gentoo.org>
CommitDate: 2018-03-29 01:59:01 +0000

    media-libs/libraw: amd64 stable
    
    Bug: https://bugs.gentoo.org/633826
    Package-Manager: Portage-2.3.26, Repoman-2.3.7

 media-libs/libraw/libraw-0.18.8.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)}
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2018-03-29 14:53:57 UTC
x86 stable
Comment 7 Tobias Klausmann (RETIRED) gentoo-dev 2018-03-31 14:18:29 UTC
Stable on alpha.
Comment 8 Markus Meier gentoo-dev 2018-04-08 10:49:29 UTC
arm stable
Comment 9 Larry the Git Cow gentoo-dev 2018-04-21 19:15:28 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b75deaef244478f53ac6b5210baccc4d8ac011d4

commit b75deaef244478f53ac6b5210baccc4d8ac011d4
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-04-21 19:15:12 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-04-21 19:15:22 +0000

    media-libs/libraw: stable 0.18.8 for hppa, bug #633826
    
    Bug: https://bugs.gentoo.org/633826
    Package-Manager: Portage-2.3.28, Repoman-2.3.9
    RepoMan-Options: --include-arches="hppa"

 media-libs/libraw/libraw-0.18.8.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)}
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2018-11-24 22:26:45 UTC
tree is clean