Summary: | <net-libs/miniupnpc-2.0.20170509: Integer signedness error (CVE-2017-8798) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | mgorny |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1450062 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
net-libs/miniupnpc-2.0.20170509 amd64 arm hppa ppc ppc64 sparc x86
dev-python/miniupnpc-2.0.20170509 amd64 ppc ppc64 x86
|
Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() commit c661ab7c8e0671112ed356b916fd0b49ba1c52f3 (HEAD -> master, origin/master, origin/HEAD) Author: Michał Górny <mgorny@gentoo.org> AuthorDate: Fri May 19 13:33:18 2017 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: Fri May 19 13:37:55 2017 dev-python/miniupnpc: Bump to 2.0.20170509 commit 32096250a641fb48dd655ed37d241d34e34c5d54 Author: Michał Górny <mgorny@gentoo.org> AuthorDate: Fri May 19 13:16:52 2017 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: Fri May 19 13:37:53 2017 net-libs/miniupnpc: Sec bump to 2.0.20170509, #618200 It seems that the SONAME didn't change from current ~arch (which is due stabilization anyway), so feel free to stabilize immediately. Once done, feel free to remove all old versions (but please remove matching dev-python/miniupnpc versions as well). @ Arches, please test and mark stable: =net-libs/miniupnpc-2.0.20170509 amd64 arm hppa ppc ppc64 sparc x86 =dev-python/miniupnpc-2.0.20170509 amd64 ppc ppc64 x86 arm stable amd64 stable x86 stable sparc stable ppc64 stable ppc stable Arches, please finish stabilizing hppa Gentoo Security Padawan ChrisADR hppa stable Downgraded. No PoC for ACE/RCE. GLSA Vote: No |