Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 622202

Summary: <sci-libs/gdal-2.2.3: Heap-buffer-overflow in GTiffDataset::OpenDir
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: sci-geosciences
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1677
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 621712    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2017-06-19 12:27:39 UTC
OSS-Fuzz is a Continuous Fuzzing for Open Source Software. See $URL for more details about the issue.
Commit fix: https://trac.osgeo.org/gdal/changeset/38470



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Amy Liffey gentoo-dev 2018-08-11 19:28:15 UTC
Fixed in 2.2.3 [1]

[1] https://github.com/OSGeo/gdal/blob/v2.2.3/gdal/frmts/gtiff/geotiff.cpp#L12244
Comment 2 Larry the Git Cow gentoo-dev 2018-08-15 08:14:59 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8a11d4f138645601f3bcf3475bd18577681b3928

commit 8a11d4f138645601f3bcf3475bd18577681b3928
Author:     Amy Liffey <amynka@gentoo.org>
AuthorDate: 2018-08-15 08:12:19 +0000
Commit:     Amy Liffey <amynka@gentoo.org>
CommitDate: 2018-08-15 08:12:19 +0000

    sci-libs/gdal: remove old affected version
    
    Bug: https://bugs.gentoo.org/621712
    Bug: https://bugs.gentoo.org/621716
    Bug: https://bugs.gentoo.org/621718
    Bug: https://bugs.gentoo.org/622202
    Bug: https://bugs.gentoo.org/623028
    Bug: https://bugs.gentoo.org/627224
    Bug: https://bugs.gentoo.org/621714
    Bug: https://bugs.gentoo.org/621720
    Closes: https://bugs.gentoo.org/663462
    Package-Manager: Portage-2.3.40, Repoman-2.3.9

 sci-libs/gdal/Manifest             |   1 -
 sci-libs/gdal/gdal-2.2.3-r1.ebuild | 289 -------------------------------------
 2 files changed, 290 deletions(-)
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-08-15 08:30:22 UTC
GLSA vote: No.