Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 662898 (CVE-2018-5801)

Summary: <media-gfx/dcraw-9.28.0: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp (CVE-2018-5801)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: graphics+disabled
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [noglsa cve]
Package list:
media-gfx/dcraw-9.28.0
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2018-08-05 23:26:45 UTC
CVE-2018-5801 (https://nvd.nist.gov/vuln/detail/CVE-2018-5801):
  NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-05 23:28:10 UTC
@ Maintainer(s): Can we start stabilization of =media-gfx/dcraw-9.28.0?
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-11-25 01:56:48 UTC
pretty please?
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2018-11-29 21:46:39 UTC
@arches, please stabilize.
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2018-12-01 20:36:10 UTC
hppa stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2018-12-01 21:03:34 UTC
ia64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2018-12-04 11:57:32 UTC
amd64 stable
Comment 7 Rolf Eike Beer archtester 2018-12-05 17:35:26 UTC
sparc stable
Comment 8 Sergei Trofimovich (RETIRED) gentoo-dev 2018-12-08 10:23:41 UTC
ppc stable
Comment 9 Sergei Trofimovich (RETIRED) gentoo-dev 2018-12-08 10:56:22 UTC
ppc64 stable
Comment 10 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-12-08 11:56:10 UTC
arm stable
Comment 11 Thomas Deutschmann (RETIRED) gentoo-dev 2018-12-09 23:52:00 UTC
x86 stable
Comment 12 Larry the Git Cow gentoo-dev 2019-01-30 13:20:21 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=eca04cdfa19adcb465128cdb574eeec9cdd3116f

commit eca04cdfa19adcb465128cdb574eeec9cdd3116f
Author:     Tobias Klausmann <klausman@gentoo.org>
AuthorDate: 2019-01-30 13:19:56 +0000
Commit:     Tobias Klausmann <klausman@gentoo.org>
CommitDate: 2019-01-30 13:19:56 +0000

    media-gfx/dcraw-9.28.0-r0: alpha stable
    
    Bug: http://bugs.gentoo.org/662898
    Signed-off-by: Tobias Klausmann <klausman@gentoo.org>

 media-gfx/dcraw/dcraw-9.28.0.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2019-03-10 04:18:27 UTC
@graphics, please clean vulnerable.
Comment 14 Aaron Bauman (RETIRED) gentoo-dev 2019-03-10 21:09:34 UTC
tree is clean.