Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635272 (CVE-2017-12613, CVE-2017-12618) - <dev-libs/{apr-1.6.3,apr-util-1.6.1}: two out of bounds access
Summary: <dev-libs/{apr-1.6.3,apr-util-1.6.1}: two out of bounds access
Status: RESOLVED FIXED
Alias: CVE-2017-12613, CVE-2017-12618
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://mail-archives.apache.org/mod_m...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks: 665156
  Show dependency tree
 
Reported: 2017-10-24 06:46 UTC by Agostino Sarubbo
Modified: 2021-12-08 08:10 UTC (History)
2 users (show)

See Also:
Package list:
dev-libs/apr-util-1.6.1-r3 dev-libs/apr-1.6.3-r3
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-10-24 06:46:37 UTC
From ${URL} :


The Apache Software Foundation and the Apache Portable Runtime
Project are proud to announce the General Availability of version
1.6.3 of the Apache Portable Runtime library (APR), as well as
version 1.6.1 of the APR Utility library (APR-util) and version
1.2.2 of the APR iconv library (APR-iconv).

APR 1.6.1 release addresses one security vulnerability;

  CVE-2017-12618; Out-of-bounds access in corrupted SDBM database.

  APR-util 1.6.0 and prior failed to validate the integrity of SDBM
  database files used by apr_sdbm*() functions, resulting in a
  possible out of bound read access. A local user with write access
  to the database can make a program or process using these functions
  crash, and cause a denial of service.

APR-util 1.6.3 release addresses one security vulnerability;

  CVE-2017-12613; Out-of-bounds array deref in apr_time_exp*() functions

  When apr_exp_time*() or apr_os_exp_time*() functions are invoked
  with an invalid month field value in APR 1.6.2 and prior, out of
  bounds memory may be accessed in converting this value to an
  apr_time_exp_t value, potentially revealing the contents of a
  different static heap value or resulting in program termination,
  and may represent an information disclosure or denial of service
  vulnerability to applications which call these APR functions with
  unvalidated external input.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Mart Raudsepp gentoo-dev 2018-09-13 21:13:01 UTC
apr was already arm64 stabled from previous bug and apr-util does not have stable arm64 keywords..
Comment 2 Agostino Sarubbo gentoo-dev 2018-09-14 09:20:43 UTC
amd64 stable
Comment 3 Sergei Trofimovich (RETIRED) gentoo-dev 2018-09-15 21:51:37 UTC
ia64 stable
Comment 4 Rolf Eike Beer archtester 2018-09-16 07:32:24 UTC
sparc done.
Comment 5 Matt Turner gentoo-dev 2018-09-16 19:53:01 UTC
ppc/ppc64 stable
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2018-09-19 17:35:36 UTC
x86 stable
Comment 7 Markus Meier gentoo-dev 2018-09-24 18:14:57 UTC
arm stable
Comment 8 Tobias Klausmann (RETIRED) gentoo-dev 2018-10-02 10:59:02 UTC
Stable on alpha.
Comment 9 Sergei Trofimovich (RETIRED) gentoo-dev 2019-04-08 07:24:57 UTC
hppa stable
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2019-04-08 13:36:21 UTC
@maintainer(s), please drop vulnerable.
Comment 11 Larry the Git Cow gentoo-dev 2019-04-20 23:58:11 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3ba92259e954426118d8f238ff53e7d632e852a1

commit 3ba92259e954426118d8f238ff53e7d632e852a1
Author:     Lars Wendler <polynomial-c@gentoo.org>
AuthorDate: 2019-04-20 23:57:25 +0000
Commit:     Lars Wendler <polynomial-c@gentoo.org>
CommitDate: 2019-04-20 23:57:25 +0000

    dev-libs/apr: Security cleanup
    
    Bug: https://bugs.gentoo.org/635272
    Package-Manager: Portage-2.3.64, Repoman-2.3.12
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 dev-libs/apr/Manifest         |   1 -
 dev-libs/apr/apr-1.5.2.ebuild | 143 ------------------------------------------
 2 files changed, 144 deletions(-)
Comment 12 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2019-04-21 00:00:02 UTC
<dev-libs/apr-util-1.6.3 is gone as well.