Summary: | <sys-libs/glibc-{2.38-r12, 2.39-r3}: Out-of-bound writes when writing escape sequence in iconv (ISO-2022-CN-EXT) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | gentoo-bgz, gordon.parton, hanno, kfm, mentalstring, steffen.weber, toolchain |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://openwall.com/lists/oss-security/2024/04/17/9 | ||
Whiteboard: | B2 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 930274, 930703 | ||
Bug Blocks: |
Description
Sam James
![]() ![]() ![]() ![]() The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3931b13e56d8a3fe3d2bcec3f86f1140bcb3217b commit 3931b13e56d8a3fe3d2bcec3f86f1140bcb3217b Author: Andreas K. Hüttel <dilfridge@gentoo.org> AuthorDate: 2024-04-18 00:38:17 +0000 Commit: Andreas K. Hüttel <dilfridge@gentoo.org> CommitDate: 2024-04-18 00:39:35 +0000 sys-libs/glibc: 2.38 and 2.39 revbump for CVE-2024-2961, GLIBC-SA-2024-0004 Bug: https://bugs.gentoo.org/930177 Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org> sys-libs/glibc/Manifest | 2 + sys-libs/glibc/glibc-2.38-r12.ebuild | 1724 ++++++++++++++++++++++++++++++++++ sys-libs/glibc/glibc-2.39-r3.ebuild | 1724 ++++++++++++++++++++++++++++++++++ 3 files changed, 3450 insertions(+) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2f55bd37a5e0c43c06a528909afb2b1e786173a3 commit 2f55bd37a5e0c43c06a528909afb2b1e786173a3 Author: Sam James <sam@gentoo.org> AuthorDate: 2024-04-18 02:42:14 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2024-04-18 02:42:14 +0000 sys-libs/glibc: keyword 2.39-r3 Bug: https://bugs.gentoo.org/930177 Signed-off-by: Sam James <sam@gentoo.org> sys-libs/glibc/glibc-2.39-r3.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c8234d44e99abfd5a655d66b63979db4ca853354 commit c8234d44e99abfd5a655d66b63979db4ca853354 Author: Sam James <sam@gentoo.org> AuthorDate: 2024-04-18 01:52:17 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2024-04-18 01:52:17 +0000 sys-libs/glibc: keyword 2.38-r12 Bug: https://bugs.gentoo.org/930177 Signed-off-by: Sam James <sam@gentoo.org> sys-libs/glibc/glibc-2.38-r12.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) *** Bug 931308 has been marked as a duplicate of this bug. *** The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=321e9a106808c3799e6007bf5459c5b6adb657a3 commit 321e9a106808c3799e6007bf5459c5b6adb657a3 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-05-06 16:20:24 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2024-05-06 16:21:25 +0000 [ GLSA 202405-17 ] glibc: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/930177 Bug: https://bugs.gentoo.org/930667 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Sam James <sam@gentoo.org> glsa-202405-17.xml | 52 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) |