Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 652910 (CVE-2018-9860)

Summary: <dev-libs/botan-2.6.0: Denial of Service
Product: Gentoo Security Reporter: Jack Lloyd <lloyd>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: alonbl, crypto+disabled, jstein, lloyd, mgorny, proxy-maint
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://botan.randombit.net/news.html
Whiteboard: B3 [noglsa cve]
Package list:
=dev-libs/botan-2.6.0
Runtime testing required: ---

Description Jack Lloyd 2018-04-10 14:02:31 UTC
Botan 2.6.0 has been released fixing CVE-2018-9860 (potential denial of service in TLS CBC decryption). 1.10.17 is not affected.

2.6.0 also fixes a miscompilation issue on x86(-64) which caused incorrect results when compiled by GCC 7.3 and certain flags such as -fno-plt.

Sorry for the churn here, OSS-Fuzz found CVE 2 days after 2.5.0 release.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2018-04-10 16:30:11 UTC
2.6.0 is not in the tree yet.
Comment 2 Larry the Git Cow gentoo-dev 2018-04-10 18:55:08 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c0e35a7714db0e1d3ffa913e50b412ff1c1cb991

commit c0e35a7714db0e1d3ffa913e50b412ff1c1cb991
Author:     Alon Bar-Lev <alonbl@gentoo.org>
AuthorDate: 2018-04-10 18:54:28 +0000
Commit:     Alon Bar-Lev <alonbl@gentoo.org>
CommitDate: 2018-04-10 18:54:58 +0000

    dev-libs/botan: version bump
    
    Bug: https://bugs.gentoo.org/652910
    Package-Manager: Portage-2.3.24, Repoman-2.3.6

 dev-libs/botan/Manifest           |  1 +
 dev-libs/botan/botan-2.6.0.ebuild | 92 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 93 insertions(+)}
Comment 3 Larry the Git Cow gentoo-dev 2018-04-18 23:31:27 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=454c09bcc33443ca8de015e90b0983073753f88d

commit 454c09bcc33443ca8de015e90b0983073753f88d
Author:     Aaron Bauman <bman@gentoo.org>
AuthorDate: 2018-04-18 23:30:34 +0000
Commit:     Aaron Bauman <bman@gentoo.org>
CommitDate: 2018-04-18 23:30:34 +0000

    dev-libs/botan: amd64 stable wrt bug #652910
    
    Bug: https://bugs.gentoo.org/652910
    Package-Manager: Portage-2.3.29, Repoman-2.3.9

 dev-libs/botan/botan-2.6.0.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)}
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2018-04-22 01:35:51 UTC
x86 stable
Comment 5 Larry the Git Cow gentoo-dev 2018-05-20 14:47:37 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=41aa3fcbfc826ae86385b1053e3a57a9185a9360

commit 41aa3fcbfc826ae86385b1053e3a57a9185a9360
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-05-20 14:47:15 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-05-20 14:47:15 +0000

    dev-libs/botan: stable 2.6.0 for ppc64, bug #652910
    
    Bug: https://bugs.gentoo.org/652910
    Package-Manager: Portage-2.3.38, Repoman-2.3.9
    RepoMan-Options: --include-arches="ppc64"

 dev-libs/botan/botan-2.6.0.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 6 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-05-26 08:07:18 UTC
ppc stable
Comment 7 Larry the Git Cow gentoo-dev 2018-05-26 08:13:50 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=13e2cb1c2f57fee406c4852b1e2d0c5eca0e873f

commit 13e2cb1c2f57fee406c4852b1e2d0c5eca0e873f
Author:     Alon Bar-Lev <alonbl@gentoo.org>
AuthorDate: 2018-05-26 08:12:35 +0000
Commit:     Alon Bar-Lev <alonbl@gentoo.org>
CommitDate: 2018-05-26 08:13:39 +0000

    dev-libs/botan: cleanup
    
    Bug: https://bugs.gentoo.org/652910
    Package-Manager: Portage-2.3.24, Repoman-2.3.6

 dev-libs/botan/Manifest           |  1 -
 dev-libs/botan/botan-2.5.0.ebuild | 92 ---------------------------------------
 2 files changed, 93 deletions(-)
Comment 8 Aaron Bauman (RETIRED) gentoo-dev 2018-05-26 14:26:56 UTC
GLSA Vote: No