Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 829189 (CVE-2021-39048) - <app-backup/tsm-8.1.13.3: multiple vulnerabilities
Summary: <app-backup/tsm-8.1.13.3: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2021-39048
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa+]
Keywords:
Depends on: 831509
Blocks: CVE-2021-3711, CVE-2021-3712
  Show dependency tree
 
Reported: 2021-12-14 17:21 UTC by Horst Prote
Modified: 2022-09-07 03:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Ebuild (tsm-8.1.13.0.ebuild,7.53 KB, text/plain)
2021-12-14 17:23 UTC, Horst Prote
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Horst Prote 2021-12-14 17:21:48 UTC
IBM published two Security Bulletins:
- Vulnerabilities in OpenSSL https://www.ibm.com/support/pages/node/6524712
- Stack-based Buffer Overflow https://www.ibm.com/support/pages/node/6524706


Reproducible: Always
Comment 1 Horst Prote 2021-12-14 17:23:48 UTC
Created attachment 758991 [details]
Ebuild

I created this ebuild in my local overlay and installed it on my servers.

Note that with this Ebuild some parts of the installion are broken. But that doesn't bother me because I only use the dsmc and the dsmj binary which work for me.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-12-16 01:03:26 UTC
Thank you for reporting! Maintainer, please bump.
Comment 3 Horst Prote 2021-12-20 10:11:30 UTC
I think I should concretize this
> Note that with this Ebuild some parts of the installion are broken.
There are binaries and .so files with unresolved soname dependencies.
Comment 4 Larry the Git Cow gentoo-dev 2022-01-19 21:49:02 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=11629c2e66238b3bf753201af27c3147e3ab5cc9

commit 11629c2e66238b3bf753201af27c3147e3ab5cc9
Author:     Andreas K. Hüttel <dilfridge@gentoo.org>
AuthorDate: 2022-01-19 21:48:28 +0000
Commit:     Andreas K. Hüttel <dilfridge@gentoo.org>
CommitDate: 2022-01-19 21:48:49 +0000

    app-backup/tsm: Version (and EAPI) bump
    
    Bug: https://bugs.gentoo.org/829189
    Bug: https://bugs.gentoo.org/788115
    Bug: https://bugs.gentoo.org/831509
    Package-Manager: Portage-3.0.30, Repoman-3.0.3
    Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org>

 app-backup/tsm/Manifest            |   1 +
 app-backup/tsm/tsm-8.1.13.3.ebuild | 244 +++++++++++++++++++++++++++++++++++++
 2 files changed, 245 insertions(+)
Comment 5 Larry the Git Cow gentoo-dev 2022-01-26 15:01:40 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=19615ea1114f61342dcd610a4bedd9e9874b6c16

commit 19615ea1114f61342dcd610a4bedd9e9874b6c16
Author:     Andreas K. Hüttel <dilfridge@gentoo.org>
AuthorDate: 2022-01-26 15:01:13 +0000
Commit:     Andreas K. Hüttel <dilfridge@gentoo.org>
CommitDate: 2022-01-26 15:01:27 +0000

    app-backup/tsm: Remove old
    
    Bug: https://bugs.gentoo.org/831509
    Bug: https://bugs.gentoo.org/829189
    Bug: https://bugs.gentoo.org/788115
    Package-Manager: Portage-3.0.30, Repoman-3.0.3
    Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org>

 app-backup/tsm/Manifest              |   1 -
 app-backup/tsm/tsm-8.1.6.0-r2.ebuild | 243 -----------------------------------
 2 files changed, 244 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5279a8876e6339a00122fd648893ecfd6bfc9de4

commit 5279a8876e6339a00122fd648893ecfd6bfc9de4
Author:     Andreas K. Hüttel <dilfridge@gentoo.org>
AuthorDate: 2022-01-26 15:00:36 +0000
Commit:     Andreas K. Hüttel <dilfridge@gentoo.org>
CommitDate: 2022-01-26 15:01:24 +0000

    app-backup/tsm: stable 8.1.13.3 for amd64
    
    Bug: https://bugs.gentoo.org/831509
    Bug: https://bugs.gentoo.org/829189
    Bug: https://bugs.gentoo.org/788115
    Package-Manager: Portage-3.0.30, Repoman-3.0.3
    Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org>

 app-backup/tsm/tsm-8.1.13.3.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-14 05:19:49 UTC
GLSA request filed
Comment 7 Larry the Git Cow gentoo-dev 2022-09-07 03:01:28 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=fe3e07b9e738d35142f3a5ca93fd91da657936e6

commit fe3e07b9e738d35142f3a5ca93fd91da657936e6
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-09-07 02:52:10 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-09-07 02:58:06 +0000

    [ GLSA 202209-02 ] IBM Spectrum Protect: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/788115
    Bug: https://bugs.gentoo.org/829189
    Bug: https://bugs.gentoo.org/831509
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202209-02.xml | 48 ++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 48 insertions(+)
Comment 8 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-07 03:19:33 UTC
GLSA released, all done!