Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 622046 (CVE-2017-9233) - <dev-libs/expat-2.2.1: External entity infinite loop DoS
Summary: <dev-libs/expat-2.2.1: External entity infinite loop DoS
Status: RESOLVED FIXED
Alias: CVE-2017-9233
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://libexpat.github.io/doc/cve-20...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-17 19:09 UTC by Sebastian Pipping
Modified: 2017-09-12 15:25 UTC (History)
2 users (show)

See Also:
Package list:
dev-libs/expat-2.2.1
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Pipping gentoo-dev 2017-06-17 19:09:11 UTC
Details at https://libexpat.github.io/doc/cve-2017-9233/ .
Comment 1 Sebastian Pipping gentoo-dev 2017-06-17 19:13:32 UTC
commit 2466807370676c8702e2512e1742cbf6a1aa1bd4
Author: Sebastian Pipping <sping@g.o>
Date:   Sat Jun 17 21:10:10 2017 +0200

    dev-libs/expat: 2.2.1 (bug #622046)
    
    Package-Manager: Portage-2.3.6, Repoman-2.3.2

 dev-libs/expat/Manifest           |  1 +
 dev-libs/expat/expat-2.2.1.ebuild | 78 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 79 insertions(+)

https://github.com/gentoo/gentoo/commit/2466807370676c8702e2512e1742cbf6a1aa1bd4
Comment 2 Agostino Sarubbo gentoo-dev 2017-06-18 14:03:29 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2017-06-20 07:03:02 UTC
x86 stable
Comment 4 Tobias Klausmann (RETIRED) gentoo-dev 2017-06-20 15:02:43 UTC
Stable on alpha.
Comment 5 Agostino Sarubbo gentoo-dev 2017-06-21 12:06:30 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2017-06-21 12:19:21 UTC
ppc64 stable
Comment 7 Markus Meier gentoo-dev 2017-06-23 04:41:10 UTC
arm stable
Comment 8 Sergei Trofimovich (RETIRED) gentoo-dev 2017-06-30 07:41:11 UTC
ia64 stable
Comment 9 Agostino Sarubbo gentoo-dev 2017-07-07 09:10:02 UTC
sparc stable
Comment 10 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-08-17 00:27:16 UTC
Arches, please finish stabilizing hppa

Gentoo Security Padawan
ChrisADR
Comment 11 Alexis Ballier gentoo-dev 2017-09-02 18:42:53 UTC
arm64 done
Comment 12 Sergei Trofimovich (RETIRED) gentoo-dev 2017-09-11 21:43:01 UTC
hppa is done (thanks to Dakon)
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2017-09-11 22:05:37 UTC
@maintainer(s), please cleanup.

GLSA Vote: No
Comment 14 Sebastian Pipping gentoo-dev 2017-09-12 13:05:46 UTC
(In reply to Aaron Bauman from comment #13)
> @maintainer(s), please cleanup.

I notice now that arches m68k, s390 and sh are stable on 2.2.0-r1 but not on 2.2.1.  Are you sure we don't stabilize these arches any more and that 2.2.0-r1 can be removed already?


# eshowkw 
Keywords for dev-libs/expat:
            |                                 |   u   |  
            | a a         p   a     n r     s |   n   |  
            | l m   h i   p   r m m i i s   p | e u s | r
            | p d a p a p c x m i 6 o s 3   a | a s l | e
            | h 6 r p 6 p 6 8 6 p 8 s c 9 s r | p e o | p
            | a 4 m a 4 c 4 6 4 s k 2 v 0 h c | i d t | o
------------+---------------------------------+-------+-------
   2.2.0-r1 | + + + + + + + + + ~ + o o + + + | 5 o 0 | gentoo
   2.2.0-r2 | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 #   | gentoo
   2.2.1    | + + + + + + + + + ~ ~ o o ~ ~ + | 6 o   | gentoo
   2.2.2    | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 #   | gentoo
   2.2.3    | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 #   | gentoo
[I]2.2.4    | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 o   | gentoo
Comment 15 Michael Palimaka (kensington) gentoo-dev 2017-09-12 13:07:19 UTC
(In reply to Sebastian Pipping from comment #14)
> (In reply to Aaron Bauman from comment #13)
> > @maintainer(s), please cleanup.
> 
> I notice now that arches m68k, s390 and sh are stable on 2.2.0-r1 but not on
> 2.2.1.  Are you sure we don't stabilize these arches any more and that
> 2.2.0-r1 can be removed already?
> 
> 
> # eshowkw 
> Keywords for dev-libs/expat:
>             |                                 |   u   |  
>             | a a         p   a     n r     s |   n   |  
>             | l m   h i   p   r m m i i s   p | e u s | r
>             | p d a p a p c x m i 6 o s 3   a | a s l | e
>             | h 6 r p 6 p 6 8 6 p 8 s c 9 s r | p e o | p
>             | a 4 m a 4 c 4 6 4 s k 2 v 0 h c | i d t | o
> ------------+---------------------------------+-------+-------
>    2.2.0-r1 | + + + + + + + + + ~ + o o + + + | 5 o 0 | gentoo
>    2.2.0-r2 | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 #   | gentoo
>    2.2.1    | + + + + + + + + + ~ ~ o o ~ ~ + | 6 o   | gentoo
>    2.2.2    | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 #   | gentoo
>    2.2.3    | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 #   | gentoo
> [I]2.2.4    | ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ o o ~ ~ ~ | 6 o   | gentoo

Those arches no longer have stable profiles, so we are no longer obliged to maintain their depgraph.
Comment 16 Sebastian Pipping gentoo-dev 2017-09-12 13:16:35 UTC
(In reply to Michael Palimaka (kensington) from comment #15)
> Those arches no longer have stable profiles, so we are no longer obliged to
> maintain their depgraph.

Alright!


commit 2f110fc7f69c366f738bbe03b74157d503fde59b
Author: Sebastian Pipping <sping@g.o>
Date:   Tue Sep 12 15:10:54 2017 +0200

    dev-libs/expat: Remove old (bug 622046)
    
    Package-Manager: Portage-2.3.8, Repoman-2.3.3

 dev-libs/expat/Manifest                            |  3 -
 dev-libs/expat/expat-2.2.0-r1.ebuild               | 91 ----------------------
 dev-libs/expat/expat-2.2.0-r2.ebuild               | 83 --------------------
 dev-libs/expat/expat-2.2.2.ebuild                  | 78 -------------------
 dev-libs/expat/expat-2.2.3.ebuild                  | 78 -------------------
 .../expat-2.1.1-CVE-2016-0718-regression.patch     | 27 -------
 6 files changed, 360 deletions(-)

https://github.com/gentoo/gentoo/commit/2f110fc7f69c366f738bbe03b74157d503fde59b
Comment 17 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-09-12 15:25:16 UTC
Thank you all. Closing as already voted as noglsa and tree is clean from vulnerable versions.

Gentoo Security Padawan
ChrisADR