Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 773289 - <app-office/mdbtools-0.9.2: Multiple vulnerabilities
Summary: <app-office/mdbtools-0.9.2: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-02-27 14:25 UTC by Sam James
Modified: 2022-08-10 04:27 UTC (History)
1 user (show)

See Also:
Package list:
app-office/mdbtools-0.9.3
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-27 14:25:53 UTC
"MDB Tools 0.9.2 is a security and bug-fix release. Due to a number of memory errors uncovered by OSS-Fuzz, all users who use MDB Tools to read data from untrusted sources are encouraged to upgrade to 0.9.2 as soon as possible.

The release also includes some minor improvements and behavior changes, described below.

libmdb:

Fix infinite loop with malformed input (oss-fuzz/28789)
Fix buffer overrun and some out of bounds memory accesses (oss-fuzz/28832 + oss-fuzz/28807)
Fix potential memory leak (oss-fuzz/28791)
Improved bounds and return value checking (oss-fuzz/29328 + oss-fuzz/29329)
Add support for numeric scale/precision on JET3 databases and floating-point column types
mdb_col_to_string now prints a warning and returns "" for any unsupported data type
Improved warning with invalid row data (#253)

[...]"
Comment 1 Larry the Git Cow gentoo-dev 2021-02-27 15:12:43 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7a7835a8ef07544cbd633b4c7793c4b1518a505d

commit 7a7835a8ef07544cbd633b4c7793c4b1518a505d
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2021-02-27 14:48:14 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-02-27 15:12:38 +0000

    app-office/mdbtools: (security) bump to 0.9.2
    
    Includes a patch rather than sed which has been
    sent upstream.
    
    URL: https://github.com/mdbtools/mdbtools/pull/261
    Bug: https://bugs.gentoo.org/697568
    Bug: https://bugs.gentoo.org/773289
    Signed-off-by: Sam James <sam@gentoo.org>

 app-office/mdbtools/Manifest                       |  1 +
 .../mdbtools-0.9.2-unixODBC-respect-libdir.patch   | 46 ++++++++++++++++
 app-office/mdbtools/mdbtools-0.9.2.ebuild          | 61 ++++++++++++++++++++++
 3 files changed, 108 insertions(+)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-27 20:18:01 UTC
Waiting for https://github.com/mdbtools/mdbtools/issues/262.
Comment 3 Larry the Git Cow gentoo-dev 2021-05-03 16:49:12 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e34887e1a4e731bf03c27e962b217e6326aafc79

commit e34887e1a4e731bf03c27e962b217e6326aafc79
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2021-05-02 07:08:56 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-05-03 16:48:57 +0000

    app-office/mdbtools: add 0.9.3
    
    Bug: https://bugs.gentoo.org/773289
    Signed-off-by: Sam James <sam@gentoo.org>

 app-office/mdbtools/Manifest              |  1 +
 app-office/mdbtools/mdbtools-0.9.3.ebuild | 59 +++++++++++++++++++++++++++++++
 2 files changed, 60 insertions(+)
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-09 04:00:58 UTC
ppc done
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-09 04:01:20 UTC
ppc64 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-09 06:00:16 UTC
amd64 done
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-09 06:00:56 UTC
x86 done
Comment 8 Rolf Eike Beer archtester 2021-05-10 13:53:32 UTC
sparc stable
Comment 9 Larry the Git Cow gentoo-dev 2021-07-24 06:22:16 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=41df5bf9be91ba8ff592c8cb6ec6d4387450b383

commit 41df5bf9be91ba8ff592c8cb6ec6d4387450b383
Author:     John Helmert III <ajak@gentoo.org>
AuthorDate: 2021-07-24 06:07:45 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2021-07-24 06:21:35 +0000

    app-office/mdbtools: drop 0.7.1-r2, 0.9.1
    
    Bug: https://bugs.gentoo.org/773289
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 app-office/mdbtools/Manifest                 |  2 -
 app-office/mdbtools/mdbtools-0.7.1-r2.ebuild | 58 ---------------------------
 app-office/mdbtools/mdbtools-0.9.1.ebuild    | 60 ----------------------------
 3 files changed, 120 deletions(-)
Comment 10 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-09 15:46:53 UTC
Request filed.
Comment 11 Larry the Git Cow gentoo-dev 2022-08-10 04:18:48 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=ac5d7a025f5b21082f32f355c3f003500c9f4432

commit ac5d7a025f5b21082f32f355c3f003500c9f4432
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-08-10 04:08:26 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-08-10 04:17:33 +0000

    [ GLSA 202208-12 ] mdbtools: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/773289
    Bug: https://bugs.gentoo.org/830371
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202208-12.xml | 44 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 44 insertions(+)
Comment 12 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-10 04:27:14 UTC
GLSA released, all done!