Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 624060 (CVE-2017-9224, CVE-2017-9225, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229)

Summary: dev-libs/oniguruma: multiple vulnerabilities
Product: Gentoo Security Reporter: Christopher Díaz Riveros (RETIRED) <chrisadr>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: normal CC: cjk
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=1466730
Whiteboard: -- []
Package list:
Runtime testing required: ---

Description Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-07-06 20:17:53 UTC
From $URL:

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during regular expression searching. A logical error involving order of validation and access in match_at() could result in an out-of-bounds read from a stack buffer.

Upstream bug:

https://github.com/kkos/oniguruma/issues/57

Upstream patch:

https://github.com/kkos/oniguruma/commit/690313a061f7a4fa614ec5cc8368b4f2284e059b
Comment 1 Akinori Hattori gentoo-dev 2017-07-20 15:58:02 UTC
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=28d415d0c3fc62cce6c5395c2c3a99199361a53a

It seems that CVE-2017-9225 is not affected to version 5.9.x.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-07-21 17:36:53 UTC
I am closing this as invalid: Ebuilds in repository were never affected.