Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 618200 (CVE-2017-8798) - <net-libs/miniupnpc-2.0.20170509: Integer signedness error (CVE-2017-8798)
Summary: <net-libs/miniupnpc-2.0.20170509: Integer signedness error (CVE-2017-8798)
Status: RESOLVED FIXED
Alias: CVE-2017-8798
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-11 15:23 UTC by Agostino Sarubbo
Modified: 2017-10-15 13:46 UTC (History)
1 user (show)

See Also:
Package list:
net-libs/miniupnpc-2.0.20170509 amd64 arm hppa ppc ppc64 sparc x86 dev-python/miniupnpc-2.0.20170509 amd64 ppc ppc64 x86
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-05-11 15:23:09 UTC
From ${URL} :

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through
v2.0 allows remote attackers to cause a denial of service or possibly
have unspecified other impact.

References:

https://github.com/tintinweb/pub/tree/master/pocs/cve-2017-8798
http://miniupnp.free.fr/files/changelog.php?file=miniupnpc-2.0.20170509.tar.gz


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2017-05-19 11:39:14 UTC
commit c661ab7c8e0671112ed356b916fd0b49ba1c52f3 (HEAD -> master, origin/master, origin/HEAD)
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: Fri May 19 13:33:18 2017
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: Fri May 19 13:37:55 2017

    dev-python/miniupnpc: Bump to 2.0.20170509

commit 32096250a641fb48dd655ed37d241d34e34c5d54
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: Fri May 19 13:16:52 2017
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: Fri May 19 13:37:53 2017

    net-libs/miniupnpc: Sec bump to 2.0.20170509, #618200


It seems that the SONAME didn't change from current ~arch (which is due stabilization anyway), so feel free to stabilize immediately. Once done, feel free to remove all old versions (but please remove matching dev-python/miniupnpc versions as well).
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-06 17:07:08 UTC
@ Arches,

please test and mark stable:

=net-libs/miniupnpc-2.0.20170509 amd64 arm hppa ppc ppc64 sparc x86

=dev-python/miniupnpc-2.0.20170509 amd64 ppc ppc64 x86
Comment 3 Markus Meier gentoo-dev 2017-06-08 05:08:18 UTC
arm stable
Comment 4 Agostino Sarubbo gentoo-dev 2017-06-08 10:17:20 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2017-06-09 10:20:53 UTC
x86 stable
Comment 6 Agostino Sarubbo gentoo-dev 2017-06-10 13:46:28 UTC
sparc stable
Comment 7 Agostino Sarubbo gentoo-dev 2017-06-13 12:32:47 UTC
ppc64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2017-06-21 11:59:30 UTC
ppc stable
Comment 9 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-08-16 14:58:07 UTC
Arches, please finish stabilizing hppa

Gentoo Security Padawan
ChrisADR
Comment 10 Sergei Trofimovich (RETIRED) gentoo-dev 2017-10-15 10:25:30 UTC
hppa stable
Comment 11 Aaron Bauman (RETIRED) gentoo-dev 2017-10-15 13:46:14 UTC
Downgraded.  No PoC for ACE/RCE.

GLSA Vote: No