Summary: | <app-arch/cpio-2.11-r3: heap-based buffer overflow flaw in list_file() (CVE-2014-9112) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | arm64, base-system, josh, sh+disabled |
Priority: | Normal | Keywords: | STABLEREQ |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1167571 | ||
Whiteboard: | B2 [glsa glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 536112 | ||
Bug Blocks: | 536010 |
Description
Agostino Sarubbo
![]() CVE-2014-9112 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9112): Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive. +*cpio-2.11-r2 (09 Jan 2015) + + 09 Jan 2015; Tony Vroon <chainsaw@gentoo.org> +cpio-2.11-r2.ebuild, + +files/cpio-2.11-security.patch: + Scavenge upstream bug fixes for heap-based buffer overflow and directory + traversal through symlinks. For security bugs #530512 and #536010. Arches, please test & mark stable: =app-arch/cpio-2.11-r2 Target stable keywords: alpha amd64 arm arm64 hppa ia64 m68k ppc ppc64 s390 sh sparc x86 x86 done! Stable on alpha. Arches, please test & mark stable: =app-arch/cpio-2.11-r3 Target stable keywords: alpha amd64 arm arm64 hppa ia64 m68k ppc ppc64 s390 sh sparc x86 (Only change is the addition of eautoreconf and removal of a now unnecessary libexec directory removal; existing alpha & x86 stable keywords transferred) Stable for HPPA. arm stable amd64 stable sparc stable ppc/ppc64/s390 stable ia64 stable With all stable arches completed, and only non-stable left setting the whiteboard appropriately. New GLSA Request filed. This issue was resolved and addressed in GLSA 201502-11 at http://security.gentoo.org/glsa/glsa-201502-11.xml by GLSA coordinator Kristian Fiskerstrand (K_F). |