Bug 18971 - harfbuzz new security issues CVE-2015-8947 and CVE-2016-2052
Summary: harfbuzz new security issues CVE-2015-8947 and CVE-2016-2052
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/695557/
Whiteboard: MGA5-32-OK MGA5-64-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-07-17 22:44 CEST by David Walser
Modified: 2016-07-27 18:50 CEST (History)
4 users (show)

See Also:
Source RPM: harfbuzz-0.9.36-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-07-17 22:44:20 CEST
A CVE has been assigned for an issue fixed in harfbuzz 1.0.6:
http://openwall.com/lists/oss-security/2016/07/17/8

A CVE is still (possibly) pending for an issue fixed in 1.0.5 detailed therein.

I have the patches backported to 0.9.36.  I'm just waiting for the last CVE.
Comment 1 Marja Van Waes 2016-07-18 07:22:10 CEST
Assigning to maintainer

CC: (none) => marja11
Assignee: bugsquad => tremyfr

Comment 2 David Walser 2016-07-19 14:56:17 CEST
CVE-2015-8947 assigned for the earlier issue:
http://openwall.com/lists/oss-security/2016/07/19/2

Patched package uploaded for Mageia 5.

Advisory:
========================

Updated harfbuzz packages fix security vulnerabilities:

Two memory access issues, including a heap-based buffer overflow (CVE-2015-8947)
and incorrect table length check (CVE-2016-2052) could lead to a denial of
service when rendering a crafted OpenType font.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8947
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2052
http://openwall.com/lists/oss-security/2016/07/17/8
http://openwall.com/lists/oss-security/2016/07/19/2
========================

Updated packages in core/updates_testing:
========================
harfbuzz-0.9.36-1.1.mga5
libharfbuzz0-0.9.36-1.1.mga5
libharfbuzz-devel-0.9.36-1.1.mga5

from harfbuzz-0.9.36-1.1.mga5.src.rpm

Assignee: tremyfr => qa-bugs
Summary: harfbuzz new security issue CVE-2016-2052 => harfbuzz new security issues CVE-2015-8947 and CVE-2016-2052

Comment 3 Brian Rockwell 2016-07-23 19:02:36 CEST
mga5-32

Installed the following.

-------------------
Rpmdrake or one of its priority dependencies needs to be updated first. Rpmdrake will then restart.

The following 4 packages are going to be installed:

- harfbuzz-0.9.36-1.1.mga5.i586
- libharfbuzz0-0.9.36-1.1.mga5.i586
- meta-task-5-28.1.mga5.noarch
- urpmi-8.06.1-1.mga5.noarch

---------------------

Read something about it breaking earlier versions of LibreOffice so tested LibreOffice Writer.  Apparently works with  some other tools like Firefox.  That seems to be working fine.

My evaluation - it is working as designed in mga5-32.

CC: (none) => brtians1

Brian Rockwell 2016-07-23 19:04:28 CEST

Whiteboard: (none) => mga5-32-ok

Comment 4 David Walser 2016-07-23 23:52:11 CEST
Firefox and Thunderbird are using a bundled harfbuzz, so your best bets to test this are chromium-browser-stable, gnome-font-viewer, libreoffice, or a webkit browser.
Comment 5 David Walser 2016-07-24 00:34:59 CEST
Fonts look fine in chromium, Mageia 5 i586.
Comment 6 Brian Rockwell 2016-07-24 00:55:55 CEST
okay - trying this in Konqueror

Noted this:  https://bugs.kde.org/show_bug.cgi?id=217472

I then follow the link to:

https://en.wikipedia.org/wiki/Shabbat

which does work with Konqueror (which is good).

I then search on Hebrew Alphabet (seems to not crash there as well.).
Comment 7 David Walser 2016-07-25 20:11:20 CEST
Fonts look fine in chromium and LibreOffice on Mageia 5 x86_64.

Whiteboard: mga5-32-ok => MGA5-32-OK MGA5-64-OK

Dave Hodgins 2016-07-26 23:23:19 CEST

Keywords: (none) => validated_update
Whiteboard: MGA5-32-OK MGA5-64-OK => MGA5-32-OK MGA5-64-OK advisory
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 8 Mageia Robot 2016-07-26 23:59:54 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0264.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2016-07-27 18:50:16 CEST

URL: (none) => http://lwn.net/Vulnerabilities/695557/


Note You need to log in before you can comment on or make changes to this bug.