CVE-2021-44847 (https://github.com/TokTok/c-toxcore/pull/1718): A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet. Please bump to 0.2.13.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f507f98aca30fe012a14ee6060a9001766aae94a commit f507f98aca30fe012a14ee6060a9001766aae94a Author: Josiah Mullins <JoMull01@protonmail.com> AuthorDate: 2021-12-21 21:22:45 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-01-07 05:06:17 +0000 net-libs/tox: Bump to version 0.2.13. Signed-off-by: Josiah Mullins <JoMull01@protonmail.com> Bug: https://bugs.gentoo.org/829650 Signed-off-by: Sam James <sam@gentoo.org> net-libs/tox/Manifest | 1 + net-libs/tox/tox-0.2.13.ebuild | 114 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 115 insertions(+)
Please file a stable bug & block this one when ready, thanks!
Thanks, please cleanup!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=55df72a6b4a3e019e583cbb3ed8682b18ad69fc3 commit 55df72a6b4a3e019e583cbb3ed8682b18ad69fc3 Author: Josiah Mullins <JoMull01@protonmail.com> AuthorDate: 2022-06-15 21:27:01 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-06-16 16:31:51 +0000 net-libs/tox: Removed old version 0.2.12-r1 Bug: https://bugs.gentoo.org/829650 Signed-off-by: Josiah Mullins <JoMull01@protonmail.com> Signed-off-by: Sam James <sam@gentoo.org> net-libs/tox/Manifest | 1 - net-libs/tox/tox-0.2.12-r1.ebuild | 115 -------------------------------------- 2 files changed, 116 deletions(-)
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=6aa77730901db859e62584749cd973266fe7fffb commit 6aa77730901db859e62584749cd973266fe7fffb Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-03-03 10:05:56 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-03-03 10:06:50 +0000 [ GLSA 202403-01 ] Tox: Remote Code Execution Bug: https://bugs.gentoo.org/829650 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202403-01.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+)