Bug 18518 - pgpdump new buffer overrun issue fixed in 0.31
Summary: pgpdump new buffer overrun issue fixed in 0.31
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/689717/
Whiteboard: has_procedure advisory MGA5-64-OK MGA...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-05-23 20:20 CEST by David Walser
Modified: 2016-06-03 20:36 CEST (History)
2 users (show)

See Also:
Source RPM: pgpdump-0.30-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-05-23 20:20:38 CEST
Upstream has released version 0.31 on May 9, fixing a potential security issue:
https://github.com/kazu-yamamoto/pgpdump/blob/master/CHANGES

Updated packages uploaded for Mageia 5 and Cauldron.

Advisory:
========================

Updated pgpdump package fixes security vulnerability:

The pgpdump package has been updated to version 0.31, fixing a buffer overrun.

References:
https://github.com/kazu-yamamoto/pgpdump/blob/master/CHANGES
========================

Updated packages in core/updates_testing:
========================
pgpdump-0.31-1.mga5

from pgpdump-0.31-1.mga5.src.rpm
Comment 1 David Walser 2016-05-23 20:21:30 CEST
You can retry Claire's test from the last update:
https://bugs.mageia.org/show_bug.cgi?id=18262#c2

Whiteboard: (none) => has_procedure

Comment 2 Lewis Smith 2016-05-28 21:14:33 CEST
Testing M5 x64

Before the update, the test referred to in Comment 1 (thanks David):
$ echo -en '\xa3\x03' | pgpdump
Old: Compressed Data Packet(tag 8)
	Comp alg - BZip2(comp 3)
pgpdump: can't uncompress without zlib/bzip2.

After the update to: pgpdump-0.31-1.mga5
$ echo -en '\xa3\x03' | pgpdump
Old: Compressed Data Packet(tag 8)
	Comp alg - BZip2(comp 3)
pgpdump: can't uncompress without zlib/bzip2.

Identical output, so OKing this update.

CC: (none) => lewyssmith
Whiteboard: has_procedure => has_procedure MGA5-64-OK

Comment 3 claire robinson 2016-06-02 23:21:30 CEST
Validating. Advisory uploaded.

Keywords: (none) => validated_update
Whiteboard: has_procedure MGA5-64-OK => has_procedure advisory MGA5-64-OK MGA5-32-OK
CC: (none) => sysadmin-bugs

Comment 4 Mageia Robot 2016-06-02 23:41:04 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0212.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2016-06-03 20:36:49 CEST

URL: http://lwn.net/Vulnerabilities/685000/ => http://lwn.net/Vulnerabilities/689717/


Note You need to log in before you can comment on or make changes to this bug.