Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 639706 (CVE-2017-16879) - <sys-libs/ncurses-6.1: Stack buffer overflow vulnerability (CVE-2017-16879)
Summary: <sys-libs/ncurses-6.1: Stack buffer overflow vulnerability (CVE-2017-16879)
Status: RESOLVED FIXED
Alias: CVE-2017-16879
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on: 648114 651302 651494
Blocks: CVE-2017-11112, CVE-2017-11113 CVE-2017-10684, CVE-2017-10685 651900
  Show dependency tree
 
Reported: 2017-12-04 02:03 UTC by GLSAMaker/CVETool Bot
Modified: 2018-06-18 17:34 UTC (History)
1 user (show)

See Also:
Package list:
=sys-libs/ncurses-6.1-r2
Runtime testing required: Yes
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-12-04 02:03:10 UTC
CVE-2017-16879 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-16879):
  Stack-based buffer overflow in the _nc_write_entry function in
  tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of
  service (application crash) or possibly execute arbitrary code via a crafted
  terminfo file, as demonstrated by tic.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-12-04 02:03:54 UTC
@Maintainers please call for stabilization when ready.

Thank you
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-03-23 22:27:43 UTC
@arches, please stabilize.
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-03-24 08:00:17 UTC
amd64 stable
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-24 21:29:54 UTC
ia64 stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-25 13:47:29 UTC
ppc stable
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-25 20:23:25 UTC
ppc64 stable
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2018-03-25 22:45:46 UTC
x86 stable
Comment 8 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-27 21:22:02 UTC
commit 1fa251eb8276ed0b1d72ca836f560f21a343c079
Author: Rolf Eike Beer <eike@sf-mail.de>
Date:   Tue Mar 27 20:23:43 2018 +0200

    sys-libs/ncurses: stable 6.1-r2 for sparc, bug #639706
Comment 9 Mart Raudsepp gentoo-dev 2018-03-28 19:47:29 UTC
arm64 stable
Comment 10 Sergei Trofimovich (RETIRED) gentoo-dev 2018-03-31 10:24:34 UTC
commit acb2cee0e20bd3943186234a8ebba17540daf7e6
Author: Jeroen Roovers <jer@gentoo.org>
Date:   Sat Mar 31 11:38:29 2018 +0200

    sys-libs/ncurses: Stable for HPPA too.
Comment 11 Matt Turner gentoo-dev 2018-04-08 06:54:42 UTC
alpha stable
Comment 12 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-04-15 17:01:24 UTC
arm stable
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2018-04-15 18:36:24 UTC
exp arches removed.

Dependent bug 651644 should not block this.

GLSA request filed.
Comment 14 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-04-16 06:44:17 UTC
(In reply to Aaron Bauman from comment #13)
> exp arches removed.
> 
> Dependent bug 651644 should not block this.
> 
> GLSA request filed.

Do not remove them at least from system-wede packages, hurts noone
Comment 15 Thomas Deutschmann (RETIRED) gentoo-dev 2018-04-17 17:58:34 UTC
m68k/s390/sh stable
Comment 16 GLSAMaker/CVETool Bot gentoo-dev 2018-04-17 18:20:14 UTC
This issue was resolved and addressed in
 GLSA 201804-13 at https://security.gentoo.org/glsa/201804-13
by GLSA coordinator Aaron Bauman (b-man).
Comment 17 Aaron Bauman (RETIRED) gentoo-dev 2018-04-17 18:21:14 UTC
re-opened for cleanup/masking.
Comment 18 Michael Boyle 2018-06-18 02:23:13 UTC
@maintainer(s), please drop vulnerable. Thank you.

Michael Boyle
Security Padawan
Comment 19 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2018-06-18 10:54:13 UTC
(In reply to Michael Boyle from comment #18)
> @maintainer(s), please drop vulnerable. Thank you.
> 
> Michael Boyle
> Security Padawan

Already done. See commit c94776f9bbcb5e37c8440b59770b8515bbe61bac
Comment 20 Thomas Deutschmann (RETIRED) gentoo-dev 2018-06-18 17:34:51 UTC
All done, repository is clean.