Summary: | <app-crypt/swtpm-0.7.1: Unchecked header size indicator against expected size | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Christopher Byrne <salah.coronya> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | proxy-maint, salah.coronya, virtualization |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
See Also: | https://github.com/gentoo/gentoo/pull/24265 | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Christopher Byrne
2022-02-18 23:38:33 UTC
Thanks for reporting! The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d2054e6abb31b24bbbeb272cd36337f50b10130e commit d2054e6abb31b24bbbeb272cd36337f50b10130e Author: Christopher Byrne <salah.coronya@gmail.com> AuthorDate: 2022-02-19 02:48:43 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-02-19 05:12:52 +0000 app-crypt/swtpm: Remove old vulnerable versions Bug: https://bugs.gentoo.org/833635 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Christopher Byrne <salah.coronya@gmail.com> Closes: https://github.com/gentoo/gentoo/pull/24265 Signed-off-by: Sam James <sam@gentoo.org> app-crypt/swtpm/Manifest | 2 -- app-crypt/swtpm/swtpm-0.6.1.ebuild | 70 -------------------------------------- app-crypt/swtpm/swtpm-0.7.0.ebuild | 70 -------------------------------------- 3 files changed, 142 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5605c2f8a4c2150f0f7caa679fc615c5f9731a5a commit 5605c2f8a4c2150f0f7caa679fc615c5f9731a5a Author: Christopher Byrne <salah.coronya@gmail.com> AuthorDate: 2022-02-19 02:47:11 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-02-19 05:12:51 +0000 app-crypt/swtpm: Bump to fix CVE-2022-23645 Bug: https://bugs.gentoo.org/833635 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Christopher Byrne <salah.coronya@gmail.com> Signed-off-by: Sam James <sam@gentoo.org> app-crypt/swtpm/Manifest | 1 + app-crypt/swtpm/swtpm-0.7.1.ebuild | 70 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 71 insertions(+) |