Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 771354 - <dev-libs/libmaxminddb-1.5.2: Possible out of memory condition
Summary: <dev-libs/libmaxminddb-1.5.2: Possible out of memory condition
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/maxmind/libmaxmind...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-02-18 19:41 UTC by Sam James
Modified: 2021-03-16 21:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-18 19:41:22 UTC
"With libmaxminddb on Windows and mmdblookup generally, there were
instances where the return value of calloc was not checked, which could
lead to issues in low memory situations or when resource limits had been
set. Reported by cve-reporting. GitHub #252."
Comment 1 Larry the Git Cow gentoo-dev 2021-02-22 07:25:00 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1cf62b5cda2f53a3a8d9e218db5b2a7ffd2b4158

commit 1cf62b5cda2f53a3a8d9e218db5b2a7ffd2b4158
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2021-02-22 05:41:30 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-02-22 07:23:55 +0000

    dev-libs/libmaxminddb: (security) bump to 1.5.2
    
    Bug: https://bugs.gentoo.org/771354
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-libs/libmaxminddb/Manifest                  |  1 +
 dev-libs/libmaxminddb/libmaxminddb-1.5.2.ebuild | 30 +++++++++++++++++++++++++
 2 files changed, 31 insertions(+)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-25 06:38:51 UTC
ppc64 done
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-25 06:39:09 UTC
ppc done
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2021-02-25 08:54:05 UTC
sparc stable
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-25 17:52:42 UTC
arm64 done
Comment 6 Agostino Sarubbo gentoo-dev 2021-02-26 08:11:58 UTC
x86 stable
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-26 13:53:45 UTC
arm done
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-26 15:18:21 UTC
amd64 done

all arches done