Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 858110 (CVE-2022-32298) - <sys-apps/toybox-0.8.8: NULL pointer dereference in httpd.c
Summary: <sys-apps/toybox-0.8.8: NULL pointer dereference in httpd.c
Status: CONFIRMED
Alias: CVE-2022-32298
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/landley/toybox/iss...
Whiteboard: ~3 [ebuild]
Keywords:
Depends on: 865749
Blocks:
  Show dependency tree
 
Reported: 2022-07-15 03:00 UTC by John Helmert III
Modified: 2023-08-11 07:14 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-07-15 03:00:25 UTC
CVE-2022-32298:

Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of Service (DoS) via unspecified vectors.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-18 02:06:14 UTC
Patch is in 0.8.8. Ping Patrick.
Comment 2 Larry the Git Cow gentoo-dev 2022-08-19 06:35:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d5277109c1b389133963301c5fdaf1f19b054567

commit d5277109c1b389133963301c5fdaf1f19b054567
Author:     Patrick Lauer <patrick@gentoo.org>
AuthorDate: 2022-08-19 06:34:05 +0000
Commit:     Patrick Lauer <patrick@gentoo.org>
CommitDate: 2022-08-19 06:35:34 +0000

    sys-apps/toybox: Add 0.8.8
    
    Also remove old
    
    Bug: https://bugs.gentoo.org/858110
    Package-Manager: Portage-3.0.30, Repoman-3.0.3
    Signed-off-by: Patrick Lauer <patrick@gentoo.org>

 sys-apps/toybox/Manifest                           |  5 +-
 sys-apps/toybox/toybox-0.8.4-r1.ebuild             | 58 ----------------------
 sys-apps/toybox/toybox-0.8.5-r1.ebuild             | 58 ----------------------
 sys-apps/toybox/toybox-0.8.7.ebuild                | 58 ----------------------
 .../{toybox-0.8.6.ebuild => toybox-0.8.8.ebuild}   |  2 +-
 5 files changed, 2 insertions(+), 179 deletions(-)