Summary: | dev-libs/openssl: rsaz_1024_mul_avx2 overflow bug on x86_64 (CVE-2017-3738) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Thomas Deutschmann (RETIRED) <whissi> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A3 [glsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 640210 |
Description
Thomas Deutschmann (RETIRED)
![]() This bug is for dev-libs/openssl:1.1. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=dfa3ddada875c129793d63fa7a5c2c49205434d9 commit dfa3ddada875c129793d63fa7a5c2c49205434d9 Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2017-12-07 18:52:39 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2017-12-07 18:53:03 +0000 dev-libs/openssl: Security cleanup Bug: https://bugs.gentoo.org/640212 Package-Manager: Portage-2.3.16, Repoman-2.3.6 dev-libs/openssl/Manifest | 4 - dev-libs/openssl/openssl-1.1.0f-r1.ebuild | 282 ----------------------------- dev-libs/openssl/openssl-1.1.0f.ebuild | 240 ------------------------- dev-libs/openssl/openssl-1.1.0g-r1.ebuild | 283 ------------------------------ dev-libs/openssl/openssl-1.1.0g.ebuild | 240 ------------------------- 5 files changed, 1049 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f4afdc625b0b3aa1bc6e0df39903f133ba0caa04 commit f4afdc625b0b3aa1bc6e0df39903f133ba0caa04 Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2017-12-07 18:50:17 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2017-12-07 18:53:02 +0000 dev-libs/openssl: Rev bump to add patch for CVE-2017-3738 Bug: https://bugs.gentoo.org/640212 Package-Manager: Portage-2.3.16, Repoman-2.3.6 dev-libs/openssl/Manifest | 2 +- .../files/openssl-1.1.0g-CVE-2017-3738.patch | 77 ++++++ dev-libs/openssl/openssl-1.1.0g-r2.ebuild | 284 +++++++++++++++++++++ 3 files changed, 362 insertions(+), 1 deletion(-)} This issue was resolved and addressed in GLSA 201712-03 at https://security.gentoo.org/glsa/201712-03 by GLSA coordinator Thomas Deutschmann (whissi). |