Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 621644

Summary: <media-libs/harfbuzz-1.7.2: Use-of-uninitialized-value in OT::RangeRecord::cmp
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: floppym, gnome, kuzetsa, leio, office, polynomial-c
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=843
Whiteboard: A3 [noglsa]
Package list:
media-libs/harfbuzz-1.7.2
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2017-06-13 07:08:30 UTC
OSS-Fuzz is a Continuous Fuzzing for Open Source Software. See $URL for more details about the issue.
Commit fix: 



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Agostino Sarubbo gentoo-dev 2017-06-13 07:11:20 UTC
(In reply to Agostino Sarubbo from comment #0)
> Commit fix: 

it is unfixed upstream
Comment 2 Andreas Sturmlechner gentoo-dev 2017-10-08 14:34:07 UTC
Is it even reported upstream?
Comment 3 kuzetsa CatSwarm (kuza for short) 2017-12-09 11:55:17 UTC
(In reply to Andreas Sturmlechner from comment #2)
> Is it even reported upstream?

I believe so:

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1856

https://github.com/harfbuzz/harfbuzz/commit/e5930722d485207ca158612a2b08816337fed7e8
Comment 4 Mike Gilbert gentoo-dev 2017-12-09 22:38:59 UTC
Should be fixed in media-libs/harfbuzz-1.7.2.
Comment 5 Mike Gilbert gentoo-dev 2017-12-09 22:39:37 UTC
*** Bug 640336 has been marked as a duplicate of this bug. ***
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2017-12-10 21:35:37 UTC
sparc stable (thanks to Rolf Eike Beer)
Comment 7 Matt Turner gentoo-dev 2017-12-10 21:49:10 UTC
amd64 stable
Comment 8 Thomas Deutschmann (RETIRED) gentoo-dev 2017-12-12 16:36:00 UTC
x86 stable
Comment 9 Markus Meier gentoo-dev 2017-12-12 18:39:04 UTC
arm stable
Comment 10 Sergei Trofimovich (RETIRED) gentoo-dev 2017-12-14 22:05:22 UTC
ia64 stable
Comment 11 Sergei Trofimovich (RETIRED) gentoo-dev 2017-12-15 23:04:18 UTC
ppc stable
Comment 12 Sergei Trofimovich (RETIRED) gentoo-dev 2017-12-15 23:07:51 UTC
ppc64 stable
Comment 13 Sergei Trofimovich (RETIRED) gentoo-dev 2017-12-23 21:19:20 UTC
hppa stable
Comment 14 Tobias Klausmann (RETIRED) gentoo-dev 2018-01-28 17:00:16 UTC
Stable on alpha.
Comment 15 Mart Raudsepp gentoo-dev 2018-03-03 02:01:08 UTC
arm64 stable; no glsa voting going on here?
Comment 16 Aaron Bauman (RETIRED) gentoo-dev 2018-04-25 19:32:42 UTC
No CVE requested for this by upstream and no PoC available.  While it is rated an A3, due to a potential for DoS, I am closing this without a GLSA due to lack of the previously mentioned items.