Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 544922 (CVE-2015-2806) - <dev-libs/libtasn1-4.4: stack overflow in DER decoder (CVE-2015-2806)
Summary: <dev-libs/libtasn1-4.4: stack overflow in DER decoder (CVE-2015-2806)
Status: RESOLVED FIXED
Alias: CVE-2015-2806
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://lists.gnu.org/archive/html/he...
Whiteboard: B2 [glsa cve]
Keywords:
Depends on: CVE-2015-3622
Blocks:
  Show dependency tree
 
Reported: 2015-03-29 12:07 UTC by Hanno Böck
Modified: 2015-09-24 17:00 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2015-03-29 12:07:22 UTC
Upstream release notes:
* Noteworthy changes in release 4.4 (released 2015-03-29) [stable]
- Corrected a two-byte stack overflow in asn1_der_decoding. Reported
  by Hanno Böck.
https://lists.gnu.org/archive/html/help-libtasn1/2015-03/msg00002.html

Commit is here:
http://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;h=4d4f992826a4962790ecd0cce6fbba4a415ce149

Please bump.
Comment 1 Alon Bar-Lev (RETIRED) gentoo-dev 2015-03-29 12:10:35 UTC
Already in tree :)
Comment 2 Hanno Böck gentoo-dev 2015-03-31 08:57:08 UTC
Can we stabilize?
Comment 3 Alon Bar-Lev (RETIRED) gentoo-dev 2015-03-31 09:00:18 UTC
(In reply to Hanno Boeck from comment #2)
> Can we stabilize?

yes, changes since last are trivial.
Comment 4 Hanno Böck gentoo-dev 2015-03-31 09:07:47 UTC
Archs, please stabilize. Target keywords:
alpha amd64 arm arm64 hppa ia64 m68k ppc ppc64 s390 sh sparc x86
Comment 5 Agostino Sarubbo gentoo-dev 2015-03-31 09:15:54 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2015-03-31 09:16:08 UTC
x86 stable
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2015-03-31 16:35:44 UTC
Stable for HPPA.
Comment 8 Markus Meier gentoo-dev 2015-04-09 20:55:25 UTC
arm stable
Comment 9 Agostino Sarubbo gentoo-dev 2015-04-13 09:46:06 UTC
alpha stable
Comment 10 Agostino Sarubbo gentoo-dev 2015-04-14 12:33:31 UTC
ia64 stable
Comment 11 Agostino Sarubbo gentoo-dev 2015-04-17 12:46:43 UTC
ppc64 stable
Comment 12 Pacho Ramos gentoo-dev 2015-04-21 19:04:44 UTC
ppc stable
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2015-04-26 13:53:59 UTC
CVE-2015-2806 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2806):
  Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4
  allows remote attackers to have unspecified impact via unknown vectors.
Comment 14 Agostino Sarubbo gentoo-dev 2015-04-29 09:19:29 UTC
sparc stable
Comment 15 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-04-30 17:41:07 UTC
stabilization moved to bug 548252 for newer version
Comment 16 GLSAMaker/CVETool Bot gentoo-dev 2015-09-24 17:00:50 UTC
This issue was resolved and addressed in
 GLSA 201509-04 at https://security.gentoo.org/glsa/201509-04
by GLSA coordinator Kristian Fiskerstrand (K_F).