Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 626340 (CVE-2017-11590) - <app-text/libgxps-0.3.0: Remote Denial of Service Attack (CVE-2017-11590)
Summary: <app-text/libgxps-0.3.0: Remote Denial of Service Attack (CVE-2017-11590)
Status: RESOLVED FIXED
Alias: CVE-2017-11590
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: C3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-07-27 09:31 UTC by Aleksandr Wagner (Kivak)
Modified: 2018-03-15 21:46 UTC (History)
1 user (show)

See Also:
Package list:
=app-text/libgxps-0.3.0 =dev-util/meson-0.41.2
Runtime testing required: No
stable-bot: sanity-check-


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-07-27 09:31:30 UTC
CVE-2017-11590 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11590):

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack. 

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1475734
https://bugzilla.gnome.org/show_bug.cgi?id=785479
Comment 1 Gilles Dartiguelongue (RETIRED) gentoo-dev 2017-08-17 23:03:02 UTC
Looks like the patch made it into the 0.3.0 release which I added to the tree two days ago.
Comment 2 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-08-18 00:06:59 UTC
(In reply to Gilles Dartiguelongue from comment #1)
> Looks like the patch made it into the 0.3.0 release which I added to the
> tree two days ago.

Thank you, please call for stabilization when necessary or let us know. 

Gentoo Security Padawan
ChrisADR
Comment 3 Stabilization helper bot gentoo-dev 2017-08-27 22:01:21 UTC
An automated check of this bug failed - repoman reported dependency errors (33 lines truncated): 

> dependency.bad app-text/libgxps/libgxps-0.3.0.ebuild: DEPEND: alpha(default/linux/alpha/13.0) ['>=dev-util/meson-0.40.0']
> dependency.bad app-text/libgxps/libgxps-0.3.0.ebuild: DEPEND: alpha(default/linux/alpha/13.0/desktop) ['>=dev-util/meson-0.40.0']
> dependency.bad app-text/libgxps/libgxps-0.3.0.ebuild: DEPEND: alpha(default/linux/alpha/13.0/desktop/gnome) ['>=dev-util/meson-0.40.0']
Comment 4 Sergei Trofimovich (RETIRED) gentoo-dev 2017-08-28 08:23:41 UTC
ia64 stable

I've also stabled
    =dev-util/meson-0.41.2
Please consider to add it to package likst.
Comment 5 Stabilization helper bot gentoo-dev 2017-08-28 09:00:52 UTC
An automated check of this bug failed - repoman reported dependency errors (28 lines truncated): 

> dependency.bad app-text/libgxps/libgxps-0.3.0.ebuild: DEPEND: alpha(default/linux/alpha/13.0) ['>=dev-util/meson-0.40.0']
> dependency.bad app-text/libgxps/libgxps-0.3.0.ebuild: DEPEND: alpha(default/linux/alpha/13.0/desktop) ['>=dev-util/meson-0.40.0']
> dependency.bad app-text/libgxps/libgxps-0.3.0.ebuild: DEPEND: alpha(default/linux/alpha/13.0/desktop/gnome) ['>=dev-util/meson-0.40.0']
Comment 6 Stabilization helper bot gentoo-dev 2017-08-28 12:01:09 UTC
An automated check of this bug succeeded - the previous repoman errors are now resolved.
Comment 7 Tobias Klausmann (RETIRED) gentoo-dev 2017-09-04 07:36:30 UTC
Stable on alpha.
Comment 8 Aaron Bauman (RETIRED) gentoo-dev 2017-09-04 14:01:53 UTC
amd64/x86 stable
Comment 9 Aaron Bauman (RETIRED) gentoo-dev 2017-09-10 22:19:04 UTC
sparc was dropped to exp.

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b5901d8f716555a1479f12313a2925fcadd177a9
Comment 10 Sergei Trofimovich (RETIRED) gentoo-dev 2017-09-25 21:43:20 UTC
ppc64 stable
Comment 11 Sergei Trofimovich (RETIRED) gentoo-dev 2017-09-26 23:04:38 UTC
ppc stable
Comment 12 Sergei Trofimovich (RETIRED) gentoo-dev 2017-11-05 18:08:05 UTC
sparc stable (thanks to Rolf Eike Beer) (also marked newer meson for ~sparc)
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2018-01-21 23:48:32 UTC
@arm, ping.
Comment 14 Stabilization helper bot gentoo-dev 2018-03-14 23:00:32 UTC
An automated check of this bug failed - the following atom is unknown:

dev-util/meson-0.41.2

Please verify the atom list.
Comment 15 Mart Raudsepp gentoo-dev 2018-03-15 02:33:54 UTC
Now done for arm and cleanup bits as part of bug 631656 (much newer meson stable since long ago too)

commit 19c768cca32e1105a0f2e2a07ae771ee8d300841
Author: Markus Meier <maekke@gentoo.org>
Date:   Wed Mar 14 21:19:28 2018 +0100

    app-text/libgxps: arm stable, bug #631656
    
    Package-Manager: Portage-2.3.24, Repoman-2.3.6
    RepoMan-Options: --include-arches="arm"

 app-text/libgxps/libgxps-0.3.0.ebuild | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

commit a4ae156e48a9157825e11d5d43e2c27ffe9ac9cf
Author: Mart Raudsepp <leio@gentoo.org>
Date:   Thu Mar 15 03:25:32 2018 +0200

    app-text/libgxps: remove old
    
    Package-Manager: Portage-2.3.19, Repoman-2.3.6

 app-text/libgxps/Manifest             |  1 -
 app-text/libgxps/libgxps-0.2.5.ebuild | 48 ------------------------------------------------
 2 files changed, 49 deletions(-)


I don't know why there is no glsa jugding during all this time, so putting glsa? in whiteboard for you.
Comment 16 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2018-03-15 21:46:42 UTC
(In reply to Mart Raudsepp from comment #15)
> 
> I don't know why there is no glsa jugding during all this time, so putting
> glsa? in whiteboard for you.

Thanks leio, GLSA Vote: No.

Closing as RESOLVED, nothing else to do.