Summary: | <sys-libs/ncurses-6.3_p20220423: segfaulting OOB read | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | normal | CC: | allenwebb, base-system, esigra |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html | ||
Whiteboard: | A3 [glsa?] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 842648 | ||
Bug Blocks: |
Description
John Helmert III
2022-04-19 02:01:13 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=638b787bdb4744f8ea4357388110a5c7f226e3b5 commit 638b787bdb4744f8ea4357388110a5c7f226e3b5 Author: Sam James <sam@gentoo.org> AuthorDate: 2022-04-28 00:45:15 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-04-28 00:46:37 +0000 sys-libs/ncurses: add 6.3_p20220423{,-r1} (unkeyworded) Includes FORTIFY_SOURCE=3 (glibc-2.35 + gcc 12+ or Clang 13(?)+ needed for that, plus not on by default) and a buffer overflow fix too. Includes -r1 w/ dropped curses symlink too. Unkeyworded for now. Bug: https://bugs.gentoo.org/839351 Signed-off-by: Sam James <sam@gentoo.org> sys-libs/ncurses/Manifest | 52 +++ sys-libs/ncurses/ncurses-6.3_p20220423-r1.ebuild | 386 +++++++++++++++++++++++ sys-libs/ncurses/ncurses-6.3_p20220423.ebuild | 383 ++++++++++++++++++++++ 3 files changed, 821 insertions(+) Note that I'm stabling an earlier version in bug 841398 which doesn't fix this in order to reduce the jumps because that version has been well tested. Then we can see about unleashing this version into ~arch. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a6b2461de765e25d009178b6c14a678eb6ed6cbf commit a6b2461de765e25d009178b6c14a678eb6ed6cbf Author: Sam James <sam@gentoo.org> AuthorDate: 2022-05-03 02:46:48 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-05-03 02:46:48 +0000 sys-libs/ncurses: keyword 6.3_p20220423 Bug: https://bugs.gentoo.org/839351 Signed-off-by: Sam James <sam@gentoo.org> sys-libs/ncurses/ncurses-6.3_p20220423.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) Please cleanup commit 7a8c3fa265d02fa74b8881a4dca3cfeb9d8a938c Author: Sam James <sam@gentoo.org> Date: Thu Jun 29 07:17:05 2023 +0100 sys-libs/ncurses: drop 6.3_p20221203-r2 |