Bug 15567 - less new security issue CVE-2014-9488
Summary: less new security issue CVE-2014-9488
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/637854/
Whiteboard: has_procedure mga4-32-ok mga4-64-ok a...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-03-25 17:33 CET by David Walser
Modified: 2015-04-10 00:45 CEST (History)
1 user (show)

See Also:
Source RPM: less-458-4.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-03-25 17:33:23 CET
OpenSuSE has issued an advisory today (March 25):
http://lists.opensuse.org/opensuse-updates/2015-03/msg00077.html

Patch checked into Mageia 4 and Cauldron SVN.  Freeze push requested.

Reproducible: 

Steps to Reproduce:
David Walser 2015-03-25 17:34:01 CET

Whiteboard: (none) => MGA5TOO, MGA4TOO

Comment 1 David Walser 2015-03-26 14:20:22 CET
Patched packages uploaded for Mageia 4 and Cauldron.

Advisory:
========================

Updated less package fixes security vulnerability:

Malformed UTF-8 data could have caused an out of bounds read in the UTF-8
decoding routines, causing an invalid read access (CVE-2014-9488).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9488
http://lists.opensuse.org/opensuse-updates/2015-03/msg00077.html
========================

Updated packages in core/updates_testing:
========================
less-458-2.1.mga4

from less-458-2.1.mga4.src.rpm

Version: Cauldron => 4
Assignee: bugsquad => qa-bugs
Whiteboard: MGA5TOO, MGA4TOO => (none)

Comment 2 David Walser 2015-03-26 17:47:13 CET
PoC information here:
https://blog.fuzzing-project.org/3-less-out-of-bounds-read-access-TFPA-0022014.html
Comment 3 claire robinson 2015-04-08 17:38:11 CEST
Testing complete mga4 64

opened a couple of PoC files with less and also

$ less /usr/share/doc/less/README.urpmi

Whiteboard: (none) => has_procedure mga4-64-ok

Comment 4 claire robinson 2015-04-08 18:24:26 CEST
Validating. Advisory uploaded.

Keywords: (none) => validated_update
Whiteboard: has_procedure mga4-64-ok => has_procedure mga4-64-ok advisory
CC: (none) => sysadmin-bugs

Comment 5 David Walser 2015-04-09 21:54:39 CEST
Thanks Claire.  I can confirm your testing results on Mageia 4 i586.

Whiteboard: has_procedure mga4-64-ok advisory => has_procedure mga4-32-ok mga4-64-ok advisory

Comment 6 Mageia Robot 2015-04-10 00:45:06 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0139.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.