Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 605202 (CVE-2016-9132) - <dev-libs/botan-{1.10.14,1.11.34}: integer overflow in BER decoder
Summary: <dev-libs/botan-{1.10.14,1.11.34}: integer overflow in BER decoder
Status: RESOLVED FIXED
Alias: CVE-2016-9132
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://botan.randombit.net/security....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-01-09 17:51 UTC by Thomas Deutschmann (RETIRED)
Modified: 2017-01-18 22:56 UTC (History)
4 users (show)

See Also:
Package list:
=dev-libs/botan-1.10.14
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-09 17:51:11 UTC
From $URL:

2016-11-27 (CVE-2016-9132) Integer overflow in BER decoder

While decoding BER length fields, an integer overflow could occur. This could occur while parsing untrusted inputs such as X.509 certificates. The overflow does not seem to lead to any obviously exploitable condition, but exploitation cannot be positively ruled out. Only 32-bit platforms are likely affected; to cause an overflow on 64-bit the parsed data would have to be many gigabytes. Bug found by Falko Strenzke, cryptosource GmbH.

Fixed in 1.10.14 and 1.11.34, all prior versions affected.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-09 17:54:41 UTC
Fixed versions are already in Gentoo repository since commit 14ab24951ea392b9e8c62aa3441ac050d6ecdf58 and c31efdd2b1cd740923f9d3d2c14870309df3cf20


@ Arches,

please test and mark stable: =dev-libs/botan-1.10.14
Comment 2 Agostino Sarubbo gentoo-dev 2017-01-10 14:57:49 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2017-01-10 15:28:00 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2017-01-11 10:54:41 UTC
sparc stable
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2017-01-14 12:32:52 UTC
Stable for HPPA.
Comment 6 Agostino Sarubbo gentoo-dev 2017-01-15 16:08:06 UTC
ppc stable
Comment 7 Agostino Sarubbo gentoo-dev 2017-01-18 10:06:26 UTC
ppc64 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 8 Alon Bar-Lev (RETIRED) gentoo-dev 2017-01-18 14:45:04 UTC
(In reply to Agostino Sarubbo from comment #7)
> Maintainer(s), please cleanup.

Done.
Comment 9 Aaron Bauman (RETIRED) gentoo-dev 2017-01-18 22:56:49 UTC
GLSA Vote: No