Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 754939 - <net-dns/c-ares-1.17.1: Denial of service (CVE-2020-8277)
Summary: <net-dns/c-ares-1.17.1: Denial of service (CVE-2020-8277)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on:
Blocks: CVE-2020-8277
  Show dependency tree
 
Reported: 2020-11-16 16:52 UTC by Sam James
Modified: 2020-12-23 20:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marek Szuba archtester gentoo-dev 2020-11-18 13:19:44 UTC
Fixed upstream in 1.17.0, which incidentally is what we would need in the tree in order to be able to package nodejs-v15.
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-18 15:56:45 UTC
@blueness, able to bump?
Comment 3 Anthony Basile gentoo-dev 2020-11-20 19:46:38 UTC
(In reply to Sam James from comment #2)
> @blueness, able to bump?

1.17.1 is on the tree
Comment 4 Anthony Basile gentoo-dev 2020-11-20 19:48:49 UTC
@arches, please proceed with stabilization

KEYWORDS="amd64 arm arm64 hppa ppc ppc64 s390 sparc x86"
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-20 23:43:21 UTC
x86 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-20 23:43:37 UTC
amd64 done
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-20 23:43:55 UTC
arm done
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-20 23:44:13 UTC
arm64 done
Comment 9 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-23 00:48:36 UTC
sparc done
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-23 01:24:49 UTC
ppc done
Comment 11 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-23 01:25:07 UTC
ppc64 done
Comment 12 Agostino Sarubbo gentoo-dev 2020-11-24 07:43:41 UTC
s390 stable
Comment 13 Sergei Trofimovich (RETIRED) gentoo-dev 2020-11-26 23:14:52 UTC
hppa stable
Comment 14 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-11-26 23:26:43 UTC
All arches done. Maintainer, please cleanup.
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2020-12-23 20:19:34 UTC
This issue was resolved and addressed in
 GLSA 202012-11 at https://security.gentoo.org/glsa/202012-11
by GLSA coordinator Thomas Deutschmann (whissi).