Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 831765 (CVE-2021-39480) - <dev-util/bingrep-0.10.0: DoS by "memory allocation failure" on crafted file
Summary: <dev-util/bingrep-0.10.0: DoS by "memory allocation failure" on crafted file
Status: RESOLVED FIXED
Alias: CVE-2021-39480
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/m4b/bingrep/issues/30
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-01-22 04:03 UTC by John Helmert III
Modified: 2022-05-23 19:24 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-22 04:03:52 UTC
CVE-2021-39480:

Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
Comment 1 Larry the Git Cow gentoo-dev 2022-05-22 19:25:32 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8db40f07870987d91f4a261d242ace8bbf815d48

commit 8db40f07870987d91f4a261d242ace8bbf815d48
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2022-05-22 19:22:55 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2022-05-22 19:23:14 +0000

    dev-util/bingrep: drop 0.8.5
    
    Closes: https://bugs.gentoo.org/831765
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-util/bingrep/Manifest             |  45 --------------
 dev-util/bingrep/bingrep-0.8.5.ebuild | 114 ----------------------------------
 2 files changed, 159 deletions(-)

Additionally, it has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=96c9775c7e74230125af163e706682a1fa0dd7a1

commit 96c9775c7e74230125af163e706682a1fa0dd7a1
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2022-05-22 19:22:12 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2022-05-22 19:23:13 +0000

    dev-util/bingrep: add 0.10.0
    
    Bug: https://bugs.gentoo.org/831765
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-util/bingrep/Manifest              |  42 +++++++++++++
 dev-util/bingrep/bingrep-0.10.0.ebuild | 106 +++++++++++++++++++++++++++++++++
 2 files changed, 148 insertions(+)
Comment 2 Georgy Yakovlev archtester gentoo-dev 2022-05-22 19:26:04 UTC
sorry for closing.
cleanup done. versions since 0.9.0 are no longer affected.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-23 19:24:03 UTC
No worries! We're all done anyway.