CVE-2019-15531 (https://nvd.nist.gov/vuln/detail/CVE-2019-15531): GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
Upstream fix: https://git.gnunet.org/libextractor.git/commit/?id=d2b032452241708bee68d02aa02092cfbfba951a
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f03e8e6318164311ede00819aa2cef46ad83cc4b commit f03e8e6318164311ede00819aa2cef46ad83cc4b Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2019-10-26 20:32:18 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2019-10-26 20:32:39 +0000 media-libs/libextractor: bump to v1.9 Bug: https://bugs.gentoo.org/695538 Package-Manager: Portage-2.3.78, Repoman-2.3.17 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> media-libs/libextractor/Manifest | 1 + .../files/libextractor-1.9-CVE-2019-15531.patch | 15 +++ media-libs/libextractor/libextractor-1.9.ebuild | 118 +++++++++++++++++++++ 3 files changed, 134 insertions(+)
x86 stable
amd64 stable
Looking good on ppc. # cat libextractor-695538.report USE tests started on Do 31. Okt 00:58:39 CET 2019 FEATURES=' test' USE='' succeeded for =media-libs/libextractor-1.9 USE='-archive -bzip2 ffmpeg -flac -gif -gsf -gstreamer -gtk jpeg -magic midi -mp4 -mpeg tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive bzip2 -ffmpeg flac -gif gsf gstreamer gtk jpeg magic -midi mp4 mpeg -tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive -bzip2 -ffmpeg flac gif -gsf -gstreamer -gtk jpeg -magic midi mp4 mpeg -tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 -ffmpeg -flac -gif -gsf -gstreamer -gtk jpeg magic midi mp4 -mpeg tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive -bzip2 ffmpeg -flac -gif -gsf -gstreamer -gtk jpeg -magic midi -mp4 mpeg -tidy tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive bzip2 ffmpeg -flac -gif gsf gstreamer gtk -jpeg -magic midi mp4 mpeg -tidy tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive -bzip2 -ffmpeg -flac -gif -gsf gstreamer gtk jpeg magic midi -mp4 -mpeg tidy tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive -bzip2 ffmpeg flac gif gsf -gstreamer gtk -jpeg -magic midi mp4 -mpeg -tidy -tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 ffmpeg -flac -gif gsf gstreamer -gtk -jpeg magic -midi -mp4 mpeg -tidy tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive -bzip2 -ffmpeg -flac gif -gsf gstreamer -gtk jpeg magic -midi mp4 -mpeg tidy tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 -ffmpeg flac -gif -gsf gstreamer -gtk jpeg -magic midi -mp4 mpeg tidy -tiff vorbis zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive -bzip2 ffmpeg flac -gif gsf gstreamer gtk jpeg magic midi -mp4 -mpeg tidy tiff vorbis zlib' succeeded for =media-libs/libextractor-1.9 revdep tests started on Do 31. Okt 02:12:01 CET 2019 FEATURES=' test' USE='' succeeded for dev-python/libextractor-python
Looking good on ppc64. # cat libextractor-695538.report USE tests started on Do 31. Okt 19:49:58 CET 2019 FEATURES=' test' USE='' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 -ffmpeg -flac gif -gsf -gstreamer gtk -jpeg -magic midi -mp4 -mpeg tidy -tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive -bzip2 -ffmpeg -flac -gif -gsf -gstreamer gtk jpeg magic midi -mp4 -mpeg tidy -tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive bzip2 -ffmpeg -flac gif -gsf gstreamer gtk jpeg -magic midi -mp4 mpeg tidy -tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 -ffmpeg -flac gif gsf gstreamer -gtk -jpeg magic -midi -mp4 mpeg -tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive -bzip2 -ffmpeg -flac gif -gsf -gstreamer gtk jpeg magic midi -mp4 -mpeg tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 ffmpeg -flac -gif -gsf gstreamer -gtk -jpeg -magic -midi -mp4 -mpeg -tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 -ffmpeg -flac gif gsf gstreamer -gtk -jpeg -magic -midi -mp4 -mpeg -tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive -bzip2 ffmpeg flac gif -gsf -gstreamer -gtk -jpeg -magic -midi -mp4 -mpeg tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='archive bzip2 ffmpeg -flac -gif gsf gstreamer -gtk jpeg -magic -midi -mp4 -mpeg tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive bzip2 ffmpeg -flac gif gsf gstreamer gtk -jpeg -magic -midi mp4 mpeg -tidy tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive bzip2 -ffmpeg -flac gif gsf -gstreamer -gtk jpeg magic -midi -mp4 mpeg -tidy -tiff vorbis zlib' succeeded for =media-libs/libextractor-1.9 USE='-archive bzip2 ffmpeg -flac -gif -gsf -gstreamer gtk -jpeg -magic midi -mp4 -mpeg tidy tiff vorbis zlib' succeeded for =media-libs/libextractor-1.9 revdep tests started on Do 31. Okt 20:35:43 CET 2019 FEATURES=' test' USE='' succeeded for dev-python/libextractor-python
ppc/ppc64 stable thanks to ernsteiswuerfel!
GLSA Vote: No!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6bfcfe0e2e9ff16339f5799db47ca978381ae095 commit 6bfcfe0e2e9ff16339f5799db47ca978381ae095 Author: Sam James (sam_c) <sam@cmpct.info> AuthorDate: 2020-03-20 00:03:29 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-03-20 01:10:03 +0000 media-libs/libextractor: Cleanup vulnerable version Bug: https://bugs.gentoo.org/695538 Signed-off-by: Sam James (sam_c) <sam@cmpct.info> Closes: https://github.com/gentoo/gentoo/pull/15019 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> media-libs/libextractor/Manifest | 1 - media-libs/libextractor/libextractor-1.8-r1.ebuild | 118 --------------------- 2 files changed, 119 deletions(-)
Repository is clean, all done!
*** Bug 767238 has been marked as a duplicate of this bug. ***