Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 711282 (CVE-2019-14495) - <net-proxy/3proxy-0.8.13: Out of bounds read (buffer overflow) (CVE-2019-14495)
Summary: <net-proxy/3proxy-0.8.13: Out of bounds read (buffer overflow) (CVE-2019-14495)
Status: RESOLVED FIXED
Alias: CVE-2019-14495
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://github.com/z3APA3A/3proxy/rel...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-03-02 02:28 UTC by Sam James
Modified: 2020-03-20 01:13 UTC (History)
2 users (show)

See Also:
Package list:
net-proxy/3proxy-0.8.13
Runtime testing required: Yes
blueknight: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-02 02:28:52 UTC
Description:
"webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface."
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2020-03-02 06:01:42 UTC
 CVE ID: CVE-2019-14495
   Summary: webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2020-03-02 06:06:08 UTC
Arches, please test and mark stable:

=net-proxy/3proxy-0.8.13

Target Keywords : "amd64 x86 ppc"

Thank you!
Comment 4 Agostino Sarubbo gentoo-dev 2020-03-14 19:46:47 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2020-03-15 18:32:00 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2020-03-15 18:43:20 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 7 Alex Efros 2020-03-19 08:06:17 UTC
(In reply to Agostino Sarubbo from comment #6)
> Maintainer(s), please cleanup.

https://github.com/gentoo/gentoo/pull/15010
Comment 8 Larry the Git Cow gentoo-dev 2020-03-20 01:12:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b7299ec1e28d8f5d972da8c10a7c12ea57cd1af6

commit b7299ec1e28d8f5d972da8c10a7c12ea57cd1af6
Author:     Alex Efros <powerman-asdf@yandex.ru>
AuthorDate: 2020-03-19 08:04:03 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2020-03-20 01:11:34 +0000

    net-proxy/3proxy: remove old versions
    
    Bug: https://bugs.gentoo.org/show_bug.cgi?id=711282
    Package-Manager: Portage-2.3.89, Repoman-2.3.20
    Signed-off-by: Aleksandr Efros <powerman-asdf@yandex.ru>
    Closes: https://github.com/gentoo/gentoo/pull/15010
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 net-proxy/3proxy/3proxy-0.8.12.ebuild            | 46 ------------------------
 net-proxy/3proxy/3proxy-0.8.9.ebuild             | 40 ---------------------
 net-proxy/3proxy/Manifest                        |  2 --
 net-proxy/3proxy/files/3proxy-0.8.8-gentoo.patch | 43 ----------------------
 4 files changed, 131 deletions(-)
Comment 9 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-20 01:13:30 UTC
GLSA Vote: No!

Repository is clean, all done!