Bug 16495 - remind new buffer overflow security issue fixed upstream in 3.1.15 (CVE-2015-5957)
Summary: remind new buffer overflow security issue fixed upstream in 3.1.15 (CVE-2015-...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/653377/
Whiteboard: MGA4TOO MGA4-32-OK MGA4-64-OK MGA5-3...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-07-29 18:00 CEST by David Walser
Modified: 2015-08-07 18:06 CEST (History)
4 users (show)

See Also:
Source RPM: remind-03.01.13-4.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-07-29 18:00:26 CEST
A CVE has been requested for a security issue fixed upstream in remind:
http://openwall.com/lists/oss-security/2015/07/29/2

The issue is fixed in version 3.1.15.  A patch to fix the issue is in the message above.

Mageia 4 and Mageia 5 are also affected.

Reproducible: 

Steps to Reproduce:
David Walser 2015-07-29 18:00:34 CEST

Whiteboard: (none) => MGA5TOO, MGA4TOO

Comment 1 Shlomi Fish 2015-07-29 19:41:07 CEST
Updates submitted to the build system.
Comment 2 David Walser 2015-07-29 20:18:18 CEST
Thanks Shlomi!

This can be tested now.  See the link in Comment 0 (and the links therein) for more details.  Advisory to come later.

Updated packages in core/updates_testing:
========================
remind-03.01.13-2.1.mga4
remind-gui-03.01.13-2.1.mga4
remind-03.01.13-4.1.mga5
remind-gui-03.01.13-4.1.mga5

from SRPMS:
remind-03.01.13-2.1.mga4.src.rpm
remind-03.01.13-4.1.mga5.src.rpm

Assignee: shlomif => qa-bugs
Whiteboard: MGA5TOO, MGA4TOO => MGA4TOO
CC: (none) => shlomif
Version: Cauldron => 5

Comment 3 William Kenney 2015-07-31 17:07:31 CEST
In VirtualBox, M4, KDE, 32-bit

Package(s) under test:
remind remind-gui

default install of remind & remind-gui

Does not seem to come with a desktop icon.

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-2.mga4.i586 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-2.mga4.i586 is already installed

I can create, modify and delete reminders in the calendar.

install remind & remind-gui from updates_testing

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-2.1.mga4.i586 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-2.1.mga4.i586 is already installed

I can create, modify and delete reminders in the calendar.
I can create, modify and delete previously created reminders in the calendar.

CC: (none) => wilcal.int

William Kenney 2015-07-31 17:07:55 CEST

Whiteboard: MGA4TOO => MGA4TOO MGA4-32-OK

Comment 4 William Kenney 2015-07-31 17:20:46 CEST
In VirtualBox, M4, KDE, 64-bit

Package(s) under test:
remind remind-gui

default install of remind & remind-gui

Does not seem to come with a desktop icon.

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-2.mga4.x86_64 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-2.mga4.x86_64 is already installed

I can create, modify and delete reminders in the calendar.

install remind & remind-gui from updates_testing

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-2.1.mga4.i586 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-2.1.mga4.i586 is already installed

I can create, modify and delete reminders in the calendar.
I can create, modify and delete previously created reminders in the calendar.
William Kenney 2015-07-31 17:21:01 CEST

Whiteboard: MGA4TOO MGA4-32-OK => MGA4TOO MGA4-32-OK MGA4-64-OK

Comment 5 William Kenney 2015-07-31 17:31:22 CEST
In VirtualBox, M5, KDE, 32-bit

Package(s) under test:
remind remind-gui

default install of remind & remind-gui

Does not seem to come with a desktop icon.

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-4.mga5.i586 is already installed

I can create, modify and delete reminders in the calendar.

install remind & remind-gui from updates_testing

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-4.1.mga5.i586 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-4.1.mga5.i586 is already installed

I can create, modify and delete reminders in the calendar.
I can create, modify and delete previously created reminders in the calendar.
William Kenney 2015-07-31 17:31:42 CEST

Whiteboard: MGA4TOO MGA4-32-OK MGA4-64-OK => MGA4TOO MGA4-32-OK MGA4-64-OK MGA5-32-OK

Comment 6 William Kenney 2015-07-31 17:40:54 CEST
In VirtualBox, M5, KDE, 64-bit

Package(s) under test:
remind remind-gui

default install of remind & remind-gui

Does not seem to come with a desktop icon.

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-4.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-4.mga5.x86_64 is already installed

I can create, modify and delete reminders in the calendar.

install remind & remind-gui from updates_testing

[root@localhost wilcal]# urpmi remind
Package remind-03.01.13-4.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi remind-gui
Package remind-gui-03.01.13-4.1.mga5.x86_64 is already installed

I can create, modify and delete reminders in the calendar.
I can create, modify and delete previously created reminders in the calendar.
William Kenney 2015-07-31 17:41:14 CEST

Whiteboard: MGA4TOO MGA4-32-OK MGA4-64-OK MGA5-32-OK => MGA4TOO MGA4-32-OK MGA4-64-OK MGA5-32-OK MGA5-64-OK

Comment 7 William Kenney 2015-07-31 17:42:01 CEST
This update works fine.
Testing complete for mga4 & mga5, 32-bit & 64-bit
Validating the update.
Could someone from the sysadmin team push to updates.
Thanks

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 8 Dave Hodgins 2015-07-31 21:02:00 CEST
Removing the validated_update keyword until an advisory is available.

Keywords: validated_update => (none)
CC: (none) => davidwhodgins

Comment 9 David Walser 2015-07-31 21:31:00 CEST
Still no response to the CVE request.  Here's an advisory for now.

Advisory:
========================

Updated remind packages fix security vulnerability:

Buffer overflow in remind before 3.1.15 in the DumpSysVar() function in
src/var.c.

References:
http://openwall.com/lists/oss-security/2015/07/29/2
http://lists.roaringpenguin.com/pipermail/remind-fans/2015/003172.html
Comment 10 William Kenney 2015-07-31 21:48:05 CEST
This update works fine.
Testing complete for mga4 & mga5, 32-bit & 64-bit
Validating the update.
Could someone from the sysadmin team push to updates.
Thanks
William Kenney 2015-07-31 21:48:25 CEST

Keywords: (none) => validated_update

Dave Hodgins 2015-08-01 18:39:06 CEST

Whiteboard: MGA4TOO MGA4-32-OK MGA4-64-OK MGA5-32-OK MGA5-64-OK => MGA4TOO MGA4-32-OK MGA4-64-OK MGA5-32-OK MGA5-64-OK advisory

Comment 11 Mageia Robot 2015-08-02 00:41:50 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0299.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

David Walser 2015-08-03 19:50:03 CEST

URL: (none) => http://lwn.net/Vulnerabilities/653377/

Comment 12 David Walser 2015-08-07 13:28:53 CEST
CVE-2015-5957 finally assigned:
http://openwall.com/lists/oss-security/2015/08/07/1

Could someone update the advisory in SVN?

Advisory:
========================

Updated remind packages fix security vulnerability:

Buffer overflow in remind before 3.1.15 in the DumpSysVar() function in
src/var.c (CVE-2015-5957).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5957
http://lists.roaringpenguin.com/pipermail/remind-fans/2015/003172.html
http://openwall.com/lists/oss-security/2015/08/07/1
David Walser 2015-08-07 13:29:03 CEST

Summary: remind new buffer overflow security issue fixed upstream in 3.1.15 => remind new buffer overflow security issue fixed upstream in 3.1.15 (CVE-2015-5957)

Comment 13 Dave Hodgins 2015-08-07 18:06:13 CEST
Advisory updated in svn.

Note You need to log in before you can comment on or make changes to this bug.