Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 468262 (CVE-2013-2038) - <sci-geosciences/gpsd-3.9: DoS (packet parser crash) in the AIS driver when processing malformed packet (CVE-2013-2038)
Summary: <sci-geosciences/gpsd-3.9: DoS (packet parser crash) in the AIS driver when p...
Status: RESOLVED FIXED
Alias: CVE-2013-2038
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-02 10:35 UTC by Agostino Sarubbo
Modified: 2014-02-02 17:57 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-02 10:35:45 UTC
From ${URL} :

A denial of service flaw was found in the way AIS driver packet parser of gpsd, a service daemon 
for mediating access to a GPS, processed certain malformed packets. A remote attacker could provide 
a specially-crafted device input that, when processed would lead to gpsd's packet parser crash 
(gpsd daemon termination).

References:
[1] http://lists.nongnu.org/archive/html/gpsd-dev/2013-05/msg00000.html

Candidate upstream patches [*]:
[2] http://git.savannah.gnu.org/cgit/gpsd.git/commit/?id=08edc49d8f63c75bfdfb480b083b0d960310f94f
[3] http://git.savannah.gnu.org/cgit/gpsd.git/commit/?id=dd9c3c2830cb8f8fd8491ce68c82698dc5538f50

--
[*] Candidate because they haven't been confirmed by GPSD upstream (yet)
    to be the correct ones to fix this problem.


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-07-03 01:01:05 UTC
Appears to have been fixed as of 3.9, maintainers please ack a stable of 3.9
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-23 15:10:20 UTC
Whoops, didn't read that closely enough. Maintainer timeout. Arches, please test and stabilize =sci-geosciences/gpsd, target arches: amd64 arm ppc ppc64 x86. Thanks!
Comment 3 Agostino Sarubbo gentoo-dev 2013-08-23 19:25:35 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-08-23 19:26:02 UTC
x86 stable
Comment 5 Markus Meier gentoo-dev 2013-08-24 10:54:26 UTC
arm stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-08-24 12:34:46 UTC
ppc64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-08-26 16:53:54 UTC
ppc stable
Comment 8 Sergey Popov (RETIRED) gentoo-dev 2013-08-30 11:15:54 UTC
Thanks for your work

GLSA vote: no
Comment 9 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-02 17:57:15 UTC
GLSA vote: no.

Closing as [noglsa]