Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 711214 (CVE-2019-1020014) - <app-emulation/docker-credential-helpers-0.6.3: Double free (CVE-2019-1020014)
Summary: <app-emulation/docker-credential-helpers-0.6.3: Double free (CVE-2019-1020014)
Status: RESOLVED FIXED
Alias: CVE-2019-1020014
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2020-03-01 20:01 UTC by Sam James
Modified: 2020-03-15 02:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-01 20:01:28 UTC
Description:
"docker-credential-helpers before 0.6.3 has a double free in the List functions."

Fix: https://github.com/docker/docker-credential-helpers/commit/87c80bfba583eadc087810d17aa631ef4e405efc

Affected versions:
- <0.6.3
Comment 1 Larry the Git Cow gentoo-dev 2020-03-03 14:54:10 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2a5e4ccac7b9a5f00df4fd7f7aa5f147cc97d828

commit 2a5e4ccac7b9a5f00df4fd7f7aa5f147cc97d828
Author:     Rafael Kitover <rkitover@gmail.com>
AuthorDate: 2020-03-01 22:50:43 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2020-03-03 14:53:45 +0000

    app-emulation/docker-credential-helpers: Drop 0.6.0
    
    Security vulnerability in versions prior to 0.6.3.
    
    Bug: https://bugs.gentoo.org/711214
    Package-Manager: Portage-2.3.85, Repoman-2.3.20
    Signed-off-by: Rafael Kitover <rkitover@gmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/14819
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 app-emulation/docker-credential-helpers/Manifest   |  1 -
 .../docker-credential-helpers-0.6.0.ebuild         | 58 ----------------------
 2 files changed, 59 deletions(-)
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-15 02:50:26 UTC
Repository is clean, all done!