Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 688734 (CVE-2018-20843) - <dev-libs/expat-2.2.7: large number of colons in input makes parser consume high amount of resources, leading to DoS (CVE-2018-20843)
Summary: <dev-libs/expat-2.2.7: large number of colons in input makes parser consume h...
Status: RESOLVED FIXED
Alias: CVE-2018-20843
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://cve.mitre.org/cgi-bin/cvename...
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-06-26 12:31 UTC by Sebastian Pipping
Modified: 2019-11-25 00:19 UTC (History)
3 users (show)

See Also:
Package list:
dev-libs/expat-2.2.7
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Pipping gentoo-dev 2019-06-26 12:31:07 UTC
Arches: amd64 arm arm64 hppa ia64 ppc ppc64 s390 sparc x86


# eshowkw 
Keywords for dev-libs/expat:
         |                             a     |       |  
         |                             m     |       |  
         |                             d   x |       |  
         |                             6   8 |       |  
         |                             4   6 |   u   |  
         | a a   a     p r           s |   | |   n   |  
         | l m   r i   p i   h m s   p f m f | e u s | r
         | p d a m a p c s x p 6 3   a b i b | a s l | e
         | h 6 r 6 6 p 6 c 8 p 8 9 s r s p s | p e o | p
         | a 4 m 4 4 c 4 v 6 a k 0 h c d s d | i d t | o
---------+-----------------------------------+-------+-------
   2.2.6 | + + + + + + + ~ + + ~ + ~ + ~ ~ ~ | 6 o 0 | gentoo
[I]2.2.7 | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ | 7 o   | gentoo

Thank you!
Comment 1 Matt Turner gentoo-dev 2019-06-26 19:04:34 UTC
(You have to set package list)
Comment 2 Sergei Trofimovich (RETIRED) gentoo-dev 2019-06-27 07:37:53 UTC
ia64 stable
Comment 3 Sergei Trofimovich (RETIRED) gentoo-dev 2019-06-27 07:40:15 UTC
ppc stable
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2019-06-27 07:41:22 UTC
ppc64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2019-06-27 07:50:34 UTC
s390 stable
Comment 6 Agostino Sarubbo gentoo-dev 2019-06-27 07:57:45 UTC
amd64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2019-06-27 09:44:28 UTC
x86 stable
Comment 8 Agostino Sarubbo gentoo-dev 2019-06-27 11:15:27 UTC
sparc stable
Comment 9 Rolf Eike Beer archtester 2019-06-27 19:31:58 UTC
hppa/sparc stable
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2019-07-23 15:14:20 UTC
arm64 stable
Comment 11 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-07-28 13:48:20 UTC
arm stable
Comment 12 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-26 21:29:25 UTC
New GLSA request filed.
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2019-11-25 00:19:20 UTC
This issue was resolved and addressed in
 GLSA 201911-08 at https://security.gentoo.org/glsa/201911-08
by GLSA coordinator Aaron Bauman (b-man).