Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 624060 (CVE-2017-9224, CVE-2017-9225, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229) - dev-libs/oniguruma: multiple vulnerabilities
Summary: dev-libs/oniguruma: multiple vulnerabilities
Status: RESOLVED INVALID
Alias: CVE-2017-9224, CVE-2017-9225, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: -- []
Keywords:
Depends on:
Blocks:
 
Reported: 2017-07-06 20:17 UTC by Christopher Díaz Riveros (RETIRED)
Modified: 2017-07-21 17:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-07-06 20:17:53 UTC
From $URL:

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during regular expression searching. A logical error involving order of validation and access in match_at() could result in an out-of-bounds read from a stack buffer.

Upstream bug:

https://github.com/kkos/oniguruma/issues/57

Upstream patch:

https://github.com/kkos/oniguruma/commit/690313a061f7a4fa614ec5cc8368b4f2284e059b
Comment 1 Akinori Hattori gentoo-dev 2017-07-20 15:58:02 UTC
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=28d415d0c3fc62cce6c5395c2c3a99199361a53a

It seems that CVE-2017-9225 is not affected to version 5.9.x.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-07-21 17:36:53 UTC
I am closing this as invalid: Ebuilds in repository were never affected.