Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 619686 (CVE-2017-6891) - <dev-libs/libtasn1-4.10-r2: asn1_find_node() based stackoverflow (CVE-2017-6891)
Summary: <dev-libs/libtasn1-4.10-r2: asn1_find_node() based stackoverflow (CVE-2017-6891)
Status: RESOLVED FIXED
Alias: CVE-2017-6891
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-25 15:32 UTC by Ian Zimmerman
Modified: 2017-10-13 22:48 UTC (History)
3 users (show)

See Also:
Package list:
dev-libs/libtasn1-4.10-r2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ian Zimmerman 2017-05-25 15:32:03 UTC
Debian summary [1]:

| Two errors in the "asn1_find_node()" function (lib/parser_aux.c)
| within GnuTLS libtasn1 version 4.10 can be exploited to cause a
| stacked-based buffer overflow by tricking a user into processing a
| specially crafted assignments file via the e.g. asn1Coding utility.

Upstream patch [2]

-- 

[1]
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863186

[2]
https://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;h=5520704d075802df25ce4ffccc010ba1641bd484
Comment 1 Alon Bar-Lev (RETIRED) gentoo-dev 2017-05-25 17:13:35 UTC
Already in tree libtasn1-4.10-r2 we can stabilize.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2017-05-26 09:00:54 UTC
CVE-2017-6891 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-6891):
  Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within
  GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based
  buffer overflow by tricking a user into processing a specially crafted
  assignments file via the e.g. asn1Coding utility.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-05-26 09:04:47 UTC
@ Arches,

please test and mark stable: =dev-libs/libtasn1-4.10-r2
Comment 4 Agostino Sarubbo gentoo-dev 2017-05-26 13:48:48 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2017-05-26 14:07:35 UTC
x86 stable
Comment 6 Agostino Sarubbo gentoo-dev 2017-05-26 15:01:39 UTC
ppc64 stable
Comment 7 Tobias Klausmann (RETIRED) gentoo-dev 2017-05-27 13:24:10 UTC
Stable on alpha.
Comment 8 Markus Meier gentoo-dev 2017-06-01 04:43:59 UTC
arm stable
Comment 9 Agostino Sarubbo gentoo-dev 2017-06-10 13:47:28 UTC
sparc stable
Comment 10 Agostino Sarubbo gentoo-dev 2017-06-10 15:20:32 UTC
ia64 stable
Comment 11 Agostino Sarubbo gentoo-dev 2017-06-21 12:00:22 UTC
ppc stable
Comment 12 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-08-16 15:01:22 UTC
Arches, please finish stabilizing hppa

Gentoo Security Padawan
ChrisADR
Comment 13 Alexis Ballier gentoo-dev 2017-09-02 18:50:37 UTC
arm64 done
Comment 14 Sergei Trofimovich (RETIRED) gentoo-dev 2017-09-29 10:30:36 UTC
hppa stable
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2017-10-13 22:48:05 UTC
This issue was resolved and addressed in
 GLSA 201710-11 at https://security.gentoo.org/glsa/201710-11
by GLSA coordinator Aaron Bauman (b-man).