Issue metadata
Sign in to add a comment
|
CrOS: Vulnerability reported in net-misc/curl |
||||||||||||||||||||||
Issue descriptionAutomated analysis has detected that the following third party packages have had vulnerabilities publicly reported. NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package. Package Name: net-misc/curl Package Version: [cpe:/a:curl:curl:7.51.0 cpe:/a:curl:libcurl:7.51.0 cpe:/a:haxx:curl:7.51.0 cpe:/a:haxx:libcurl:7.51.0] Advisory: CVE-2018-1000005 Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2018-1000005 CVSS severity score: 6.4/10.0 Confidence: high Description: libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer data once appended a string like `:` to the target buffer, while this was recently changed to `: ` (a space was added after the colon) but the following math wasn't updated correspondingly. When accessed, the data is read out of bounds and causes either a crash or that the (too large) data gets passed to client write. This could lead to a denial-of-service situation or an information disclosure if someone has a service that echoes back or uses the trailers for something.
,
Feb 12 2018
https://chromium-review.googlesource.com/c/chromiumos/overlays/portage-stable/+/914810
,
Feb 14 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromiumos/overlays/portage-stable/+/63aa5b34f725b2291618c074ebb8d30da2ba957f commit 63aa5b34f725b2291618c074ebb8d30da2ba957f Author: Brian Norris <briannorris@chromium.org> Date: Wed Feb 14 05:16:47 2018 curl: upgraded package to upstream Upgraded net-misc/curl to version 7.58.0 on amd64, arm BUG= chromium:811049 TEST=precq; local tests Change-Id: I4fdf70cdb47e4bb65aabf3993d77958413c21cf8 Signed-off-by: Brian Norris <briannorris@chromium.org> Reviewed-on: https://chromium-review.googlesource.com/914810 Reviewed-by: Mike Frysinger <vapier@chromium.org> [modify] https://crrev.com/63aa5b34f725b2291618c074ebb8d30da2ba957f/net-misc/curl/Manifest [modify] https://crrev.com/63aa5b34f725b2291618c074ebb8d30da2ba957f/net-misc/curl/metadata.xml [add] https://crrev.com/63aa5b34f725b2291618c074ebb8d30da2ba957f/metadata/md5-cache/net-misc/curl-7.58.0 [rename] https://crrev.com/63aa5b34f725b2291618c074ebb8d30da2ba957f/net-misc/curl/curl-7.58.0.ebuild [delete] https://crrev.com/abfd741497a15762e0fb2f69637d4e6f0f9ff161/metadata/md5-cache/net-misc/curl-7.57.0 [delete] https://crrev.com/abfd741497a15762e0fb2f69637d4e6f0f9ff161/net-misc/curl/files/curl-7.55.1-fix-build.patch
,
Feb 14 2018
AIUI, this isn't urgent, so probably doesn't need ported to any branches? Closing.
,
Feb 14 2018
,
Feb 20 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromiumos/overlays/portage-stable/+/8ef973467f578205d21903014a98fe0d714875b7 commit 8ef973467f578205d21903014a98fe0d714875b7 Author: Brian Norris <briannorris@chromium.org> Date: Tue Feb 20 23:30:18 2018 curl: upgraded package to upstream Upgraded net-misc/curl to version 7.58.0 on amd64, arm Changed EAPI to 5, based on CL:919534 BUG= chromium:811049 ,b:73183479 TEST=precq; local tests Change-Id: I4fdf70cdb47e4bb65aabf3993d77958413c21cf8 Signed-off-by: Brian Norris <briannorris@chromium.org> Reviewed-on: https://chromium-review.googlesource.com/914810 Reviewed-by: Mike Frysinger <vapier@chromium.org> (cherry picked from commit 63aa5b34f725b2291618c074ebb8d30da2ba957f) Reviewed-on: https://chromium-review.googlesource.com/927142 Commit-Queue: Daniel Wang <wonderfly@google.com> Tested-by: Daniel Wang <wonderfly@google.com> [modify] https://crrev.com/8ef973467f578205d21903014a98fe0d714875b7/net-misc/curl/Manifest [modify] https://crrev.com/8ef973467f578205d21903014a98fe0d714875b7/net-misc/curl/metadata.xml [add] https://crrev.com/8ef973467f578205d21903014a98fe0d714875b7/metadata/md5-cache/net-misc/curl-7.58.0 [rename] https://crrev.com/8ef973467f578205d21903014a98fe0d714875b7/net-misc/curl/curl-7.58.0.ebuild [delete] https://crrev.com/6505549ac10878b487c95e83ca8e6f097a5ae83d/metadata/md5-cache/net-misc/curl-7.57.0 [delete] https://crrev.com/6505549ac10878b487c95e83ca8e6f097a5ae83d/net-misc/curl/files/curl-7.55.1-fix-build.patch
,
May 23 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by allenwebb@chromium.org
, Feb 12 2018Owner: briannorris@chromium.org
Status: Assigned (was: Untriaged)