Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 618250 (CVE-2017-7483) - <x11-terms/rxvt-2.7.10-r5: stabilization request for overflow bug (CVE-2017-7483)
Summary: <x11-terms/rxvt-2.7.10-r5: stabilization request for overflow bug (CVE-2017-7...
Status: RESOLVED WONTFIX
Alias: CVE-2017-7483
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Deadline: 2017-06-17
Assignee: Jason A. Donenfeld
URL: http://seclists.org/oss-sec/2017/q2/185
Whiteboard: B3 [noglsa cve cleanup+]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2017-05-11 20:05 UTC by Jason A. Donenfeld
Modified: 2017-06-22 01:32 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jason A. Donenfeld gentoo-dev 2017-05-11 20:05:33 UTC
I committed x11-terms/rxvt-2.7.10-r5 to the tree and immediately stabilized it, as it has no maintainer, and the patch is exceedingly simple and makes zero architecture-specific changes. The patch is a fix for CVE-2017-7483. This bug is to inform the archs about this stabilization change, as well as for the security project to track this particular security-sensitive change.

I left x11-terms/rxvt-2.7.10-r4 in the tree for the time being. If somebody from arches can confirm that, while somewhat out of the standard procedure, this isn't an entirely horrible change, then I'll go ahead and remove the old (vulnerable) ebuild.
Comment 1 Jason A. Donenfeld gentoo-dev 2017-05-11 20:07:49 UTC
Assigning this bug to myself, since the package has no maintainer, and I've thus far made the ebuild changes. If somebody from archs would like to take ownership of this, however, feel free to do so.
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2017-05-12 04:31:59 UTC
Jason, thank you.

Added ago so he could take a look. Also base on Email we could drop the package as well, and just add to the GLSA to replace with rxvt-unicode, as resolution.
Comment 3 Jason A. Donenfeld gentoo-dev 2017-05-16 21:21:56 UTC
As announced on gentoo-dev, this package has now been masked for removal in 30 days: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c50296e8e46086273f5d02e7a2a55e8b66f0d547
Comment 4 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2017-06-17 08:40:45 UTC
commit 9b7fbeb61d5c854a023c8e45a5184afa7f6f7997
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: Sat Jun 17 10:24:57 2017
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: Sat Jun 17 10:39:58 2017

    x11-terms/rxvt: Remove last-rited pkg, #618250
Comment 5 deference 2017-06-17 19:00:48 UTC
I can't tell if you have actually removed this package yet. But it is worth wile pointing out that it's lack of support for UTF-8 makes it an ideal candidate for testing CLI programs portability to a locale of C or UTF-8 in the presence of a non-UTF-8 aware terminal.