Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 881525 (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320, CVE-2022-39347, CVE-2022-41877) - <net-misc/freerdp-2.9.0: multiple vulnerabilities
Summary: <net-misc/freerdp-2.9.0: multiple vulnerabilities
Status: IN_PROGRESS
Alias: CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320, CVE-2022-39347, CVE-2022-41877
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/FreeRDP/FreeRDP/re...
Whiteboard: B3 [stable]
Keywords:
Depends on: 881835
Blocks:
  Show dependency tree
 
Reported: 2022-11-16 17:07 UTC by John Helmert III
Modified: 2022-11-19 22:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-16 17:07:04 UTC
Release notes say:

"* Backported #8403: Fixed multiple client side input validation issues
  (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319,
         CVE-2022-39320, CVE-2022-41877, CVE-2022-39347)"

TRUE and a FALSE, so I'd be very surprised if this fixes 7 different
CVEs. Nevertheless, please bump to 2.9.0
Comment 1 jospezial 2022-11-17 20:57:37 UTC Comment hidden (obsolete)
Comment 2 Larry the Git Cow gentoo-dev 2022-11-18 20:43:31 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0f3a6469bc2be992e106945747c997e5819d5f7d

commit 0f3a6469bc2be992e106945747c997e5819d5f7d
Author:     Mike Gilbert <floppym@gentoo.org>
AuthorDate: 2022-11-17 21:20:03 +0000
Commit:     Mike Gilbert <floppym@gentoo.org>
CommitDate: 2022-11-18 20:43:22 +0000

    net-misc/freerdp: add 2.9.0
    
    Bug: https://bugs.gentoo.org/881525
    Signed-off-by: Mike Gilbert <floppym@gentoo.org>

 net-misc/freerdp/Manifest             |   1 +
 net-misc/freerdp/freerdp-2.9.0.ebuild | 124 ++++++++++++++++++++++++++++++++++
 2 files changed, 125 insertions(+)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-18 21:19:15 UTC
(In reply to John Helmert III from comment #0)
> Release notes say:
> 
> "* Backported #8403: Fixed multiple client side input validation issues
>   (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319,
>          CVE-2022-39320, CVE-2022-41877, CVE-2022-39347)"
> 
> TRUE and a FALSE, so I'd be very surprised if this fixes 7 different
> CVEs. Nevertheless, please bump to 2.9.0

Hm, my script mangled my comment. I meant to say that the patch (https://github.com/FreeRDP/FreeRDP/pull/8403/files) only flip-flops a TRUE and a FALSE, so I'd be very surprised if this fixes 7 different CVEs.

Anyway, thank you for bumping! Please stabilize when ready. Any idea about the impact?
Comment 4 Mike Gilbert gentoo-dev 2022-11-18 21:30:00 UTC
(In reply to John Helmert III from comment #3)

I think they simply referenced the wrong PR for the CVE fixes. This one appears to be more relevant:

https://github.com/FreeRDP/FreeRDP/pull/8380
Comment 6 Mike Gilbert gentoo-dev 2022-11-19 17:18:00 UTC
The NIST NVD rates these as significantly more severe than the GHSA ratings.