Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 766018 - <app-text/htmldoc-1.9.11: Multiple vulnerabilities
Summary: <app-text/htmldoc-1.9.11: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2021-01-18 16:26 UTC by Sam James
Modified: 2021-01-28 03:00 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-18 16:26:34 UTC
Fixed in 1.9.1:
* "Fix buffer underflow for short (invalid) HTML comments"

https://github.com/michaelrsweet/htmldoc/issues/316

Fixed in 1.9.5:
* "Fix buffer underflow"

https://github.com/michaelrsweet/htmldoc/issues/338

Fixed in 1.9.6:
* "Fixed a buffer underflow bug discovered by AddressSanitizer."

Fixed in 1.9.8:
* "Fixed a buffer underflow issue"

https://github.com/michaelrsweet/htmldoc/issues/370
Comment 1 NATTkA bot gentoo-dev 2021-01-18 16:28:52 UTC Comment hidden (obsolete)
Comment 2 Agostino Sarubbo gentoo-dev 2021-01-22 16:54:51 UTC
amd64 stable
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-22 22:29:19 UTC
sparc done
Comment 4 Agostino Sarubbo gentoo-dev 2021-01-24 12:12:04 UTC
x86 stable
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-24 13:33:39 UTC
ppc64 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-24 13:35:17 UTC
ppc done

all arches done
Comment 7 Larry the Git Cow gentoo-dev 2021-01-24 20:21:07 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=024a602a7a316718dece30757a0ffc5840658999

commit 024a602a7a316718dece30757a0ffc5840658999
Author:     John Helmert III <jchelmert3@posteo.net>
AuthorDate: 2021-01-24 19:48:08 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-01-24 20:21:01 +0000

    app-text/htmldoc: security cleanup (drop <1.9.11)
    
    Bug: https://bugs.gentoo.org/766018
    
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: John Helmert III <jchelmert3@posteo.net>
    Closes: https://github.com/gentoo/gentoo/pull/19197
    Signed-off-by: Sam James <sam@gentoo.org>

 app-text/htmldoc/Manifest              |  1 -
 app-text/htmldoc/htmldoc-1.8.30.ebuild | 44 ----------------------------------
 2 files changed, 45 deletions(-)