Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability Roundup 29 #32117

Closed
16 of 17 tasks
ckauhaus opened this issue Nov 27, 2017 · 13 comments
Closed
16 of 17 tasks

Vulnerability Roundup 29 #32117

ckauhaus opened this issue Nov 27, 2017 · 13 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Nov 27, 2017

Obtained via vulnix -j $(nix-instantiate -I nixpkgs=. nixos/release-small.nix) on 2f1a818. Cleaned up manually for CVEs already present in #30959. May contain false positives.

libid3tag-0.15.1b (search, files)

pcre-8.41 (search, files)

pcre2-10.23 (search, files)

rpcbind-0.2.4 (search, files)

rsync-3.1.2 (search, files)

systemd-234 (search, files)

wpa_supplicant-2.6 (search, files)

@adisbladis
Copy link
Member

rpcbind resolved in #32119

@adisbladis
Copy link
Member

All of the wpa_supplicant CVEs are from KRACK Attacks which is already patched.

@pbogdan
Copy link
Member

pbogdan commented Nov 27, 2017

rsync one doesn't seem applicable being introduced in a development version after 3.1.2 was released - https://security-tracker.debian.org/tracker/CVE-2017-15994

@pbogdan
Copy link
Member

pbogdan commented Nov 27, 2017

libid3tag-0.15.1b CVE-2017-11550 looks to be covered by the Debian patches we include.

@andir
Copy link
Member

andir commented Nov 28, 2017

I opened a PR to port the systemd fix to our systemd fork: NixOS/systemd#14

@adisbladis
Copy link
Member

@adisbladis
Copy link
Member

adisbladis commented Nov 28, 2017

Redhat has closed CVE-2017-11164 with WONTFIX status https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-11164

@globin
Copy link
Member

globin commented Nov 28, 2017

@andir could you bump the systemd derivation?

@andir
Copy link
Member

andir commented Nov 28, 2017 via email

@adisbladis
Copy link
Member

Gentoo also has doubts whether CVE-2017-11164 is a valid bug or not https://bugs.gentoo.org/show_bug.cgi?id=CVE-2017-11164

I'm inclined to agree so I'm ticking this box.

vcunat added a commit that referenced this issue Nov 29, 2017
There are security fixes in multiple packages /cc #32117,
so I'm merging a little earlier, with a few thousand jobs
still not finished on Hydra for x86_64-darwin and aarch64-linux.
@ckauhaus
Copy link
Contributor Author

ckauhaus commented Dec 4, 2017

Got anyone an idea what's going on with CVE-2017-11551 (libid3tag)?

@7c6f434c
Copy link
Member

7c6f434c commented Dec 5, 2017

Quick search shows that: CVE-2017-11551 seems to be OOM-only, if I understand correctly it enforces allocation of stupid amount of memory.

After a quick search I have a suspicion that there is still no patch available.

@ckauhaus
Copy link
Contributor Author

ckauhaus commented Dec 8, 2017

I think we can safely close this issue - I'll do another roundup soon.

@ckauhaus ckauhaus closed this as completed Dec 8, 2017
@vcunat vcunat added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Feb 25, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

7 participants