New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 728987 link

Starred by 1 user

Issue metadata

Status: Archived
Owner:
Last visit > 30 days ago
Closed: Jun 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in sys-libs/zlib

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Jun 2 2017

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: sys-libs/zlib
Package Version: [cpe:/a:gnu:zlib:1.2.8]

Advisory: CVE-2016-9841
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2016-9841
  CVSS severity score: 7.5/10.0
  Confidence: high
  Description:

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Advisory: CVE-2016-9843
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2016-9843
  CVSS severity score: 7.5/10.0
  Confidence: high
  Description:

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.


 
Components: OS>Packages
Labels: Security_Severity-High Security_Impact-Stable
Owner: benchan@chromium.org
Status: Assigned (was: Untriaged)
benchan: Looks like you updated zlib a long time ago. Would you happen to be the right owner for these? Feel free to pass it back to me if not.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 6 2017

Labels: M-59
Cc: vapier@chromium.org benchan@chromium.org
Owner: andreyu@google.com
I believe +andreyu is already working on updating zlib

Comment 4 by andreyu@google.com, Jun 6 2017

Labels: Merge-Request-59
https://chromium-review.googlesource.com/c/520704/

Comment 5 by andreyu@google.com, Jun 6 2017

Status: Fixed (was: Assigned)
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 6 2017

Labels: -Merge-Request-59 Merge-Review-59 Hotlist-Merge-Review
This bug requires manual review: Request affecting a post-stable build
Please contact the milestone owner if you have questions.
Owners: amineer@(Android), cmasso@(iOS), gkihumba@(ChromeOS), Abdul Syed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Jun 7 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: Merge-Rejected-59
59 just went stable. Is this urgent? If not, please target 60

Comment 9 by gkihumba@google.com, Jun 16 2017

Labels: -M-59 -Merge-Review-59 M-60
Project Member

Comment 10 by sheriffbot@chromium.org, Sep 13 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 11 by dchan@chromium.org, Jan 22 2018

Status: Archived (was: Fixed)

Sign in to add a comment