| Summary: | opencc new security issue CVE-2018-16982 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, lewyssmith, marja11, mhrambo3501, smelror, sysadmin-bugs, tarazed25 |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-64-OK | ||
| Source RPM: | opencc-1.0.5-2.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-10-26 19:58:22 CEST
David Walser
2018-10-26 19:58:46 CEST
Whiteboard:
(none) =>
MGA6TOO Assigning to all packagers collectively, since there is no registered maintainer for this package. Assignee:
bugsquad =>
pkg-bugs Patched package uploaded for cauldron and Mageia 6. Advisory: ======================== Updated opencc package fixes security vulnerability: It was discovered that opencc contained an out of bounds pointer in BinaryDict.cpp which could lead to segment fault and a Denial of Service (CVE-2018-16982). References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GDWZHBV4B3VZTM4ACXQMZKSLTIKFJUUO/ https://github.com/BYVoid/OpenCC/issues/303 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16982 ======================== Updated packages in core/updates_testing: ======================== lib64opencc2-1.0.3-3.1.mga6 lib64opencc-devel-1.0.3-3.1.mga6 opencc-1.0.3-3.1.mga6 from opencc-1.0.3-3.1.mga6.src.rpm CC:
(none) =>
mrambo Mageia 6, x86_64 CVE-2018-16982 https://github.com/BYVoid/OpenCC/issues/303 $ opencc_dict -i keyoffsetPOC -o temp.txt -f ocd -t text Segmentation fault (core dumped) $ opencc_dict -i ValueOffsetPOC -o temp.txt -f ocd -t text Segmentation fault (core dumped) Clean update of the packages. Ran the POC tests again. $ opencc_dict -i keyoffsetPOC -o temp.txt -f ocd -t text Invalid format: Invalid OpenCC binary dictionary (keyOffset) $ opencc_dict -i ValueOffsetPOC -o temp.txt -f ocd -t text Invalid format: Invalid OpenCC binary dictionary (valueOffset) opencc has a --help facility but not knowing anything about input file formats I left this alone. Clean update and positive POC tests so this is OK for 64-bits. CC:
(none) =>
tarazed25
Thomas Andrews
2018-11-09 22:17:14 CET
Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0443.html Status:
NEW =>
RESOLVED |