Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 670026 (CVE-2018-16839, CVE-2018-16840, CVE-2018-16842) - <net-misc/curl-7.62.0 - multiple vulnerabilities
Summary: <net-misc/curl-7.62.0 - multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2018-16839, CVE-2018-16840, CVE-2018-16842
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on: 670134
Blocks: CVE-2018-14618
  Show dependency tree
 
Reported: 2018-10-31 13:44 UTC by Jeroen Roovers (RETIRED)
Modified: 2019-03-10 19:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2018-10-31 13:44:43 UTC
CVE-2018-16839: SASL password overflow via integer overflow
CVE-2018-16840: use-after-free in handle close
CVE-2018-16842: warning message out-of-buffer read
Comment 1 Larry the Git Cow gentoo-dev 2018-10-31 13:46:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1e27631c9fd6a7055e35628a195fd14c18bc9a1f

commit 1e27631c9fd6a7055e35628a195fd14c18bc9a1f
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2018-10-31 13:43:47 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2018-10-31 13:46:14 +0000

    net-misc/curl: Version 7.62.0
    
    Package-Manager: Portage-2.3.51, Repoman-2.3.11
    Bug: https://bugs.gentoo.org/670026
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 net-misc/curl/Manifest           |   1 +
 net-misc/curl/curl-7.62.0.ebuild | 247 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 248 insertions(+)
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-01-17 20:08:24 UTC
Cleaned vuln versions after arm stabilization due to long term overdue
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2019-03-10 19:49:07 UTC
This issue was resolved and addressed in
 GLSA 201903-03 at https://security.gentoo.org/glsa/201903-03
by GLSA coordinator Aaron Bauman (b-man).