[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#879501: marked as done (CVE-2017-15670)



Your message dated Sun, 19 Nov 2017 12:21:43 +0000
with message-id <E1eGObX-000Ink-DU@fasolo.debian.org>
and subject line Bug#879501: fixed in glibc 2.26-0experimental0
has caused the Debian Bug report #879501,
regarding CVE-2017-15670
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
879501: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=879501
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: libc6
Version: 2.24-17
Severity: important
Tags: security

Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15670:
The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one
error leading to a heap-based buffer overflow in the glob function in
glob.c, related to the processing of home directories using the ~ operator
followed by a long string.

Bug is here: https://sourceware.org/bugzilla/show_bug.cgi?id=22320

Fixes:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c369d66e5426a30e4725b100d5cd28e372754f90 (master)
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=a76376df7c07e577a9515c3faa5dbd50bda5da07 (release/2.26/master)

Cheers,
        Moritz

--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.26-0experimental0

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 879501@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 19 Nov 2017 12:49:13 +0100
Source: glibc
Binary: libc-bin libc-dev-bin libc-l10n glibc-doc glibc-source locales locales-all nscd multiarch-support libc6 libc6-dev libc6-dbg libc6-pic libc6-udeb libc6.1 libc6.1-dev libc6.1-dbg libc6.1-pic libc6.1-udeb libc0.3 libc0.3-dev libc0.3-dbg libc0.3-pic libc0.3-udeb libc0.1 libc0.1-dev libc0.1-dbg libc0.1-pic libc0.1-udeb libc6-i386 libc6-dev-i386 libc6-sparc libc6-dev-sparc libc6-sparc64 libc6-dev-sparc64 libc6-s390 libc6-dev-s390 libc6-amd64 libc6-dev-amd64 libc6-powerpc libc6-dev-powerpc libc6-ppc64 libc6-dev-ppc64 libc6-mips32 libc6-dev-mips32 libc6-mipsn32 libc6-dev-mipsn32 libc6-mips64 libc6-dev-mips64 libc0.1-i386 libc0.1-dev-i386 libc6-x32 libc6-dev-x32 libc6-xen libc0.3-xen libc6.1-alphaev67
Architecture: source
Version: 2.26-0experimental0
Distribution: experimental
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Description:
 glibc-doc  - GNU C Library: Documentation
 glibc-source - GNU C Library: sources
 libc-bin   - GNU C Library: Binaries
 libc-dev-bin - GNU C Library: Development binaries
 libc-l10n  - GNU C Library: localization files
 libc0.1    - GNU C Library: Shared libraries
 libc0.1-dbg - GNU C Library: detached debugging symbols
 libc0.1-dev - GNU C Library: Development Libraries and Header Files
 libc0.1-dev-i386 - GNU C Library: 32bit development libraries for AMD64
 libc0.1-i386 - GNU C Library: 32bit shared libraries for AMD64
 libc0.1-pic - GNU C Library: PIC archive library
 libc0.1-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc0.3    - GNU C Library: Shared libraries
 libc0.3-dbg - GNU C Library: detached debugging symbols
 libc0.3-dev - GNU C Library: Development Libraries and Header Files
 libc0.3-pic - GNU C Library: PIC archive library
 libc0.3-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc0.3-xen - GNU C Library: Shared libraries [Xen version]
 libc6      - GNU C Library: Shared libraries
 libc6-amd64 - GNU C Library: 64bit Shared libraries for AMD64
 libc6-dbg  - GNU C Library: detached debugging symbols
 libc6-dev  - GNU C Library: Development Libraries and Header Files
 libc6-dev-amd64 - GNU C Library: 64bit Development Libraries for AMD64
 libc6-dev-i386 - GNU C Library: 32-bit development libraries for AMD64
 libc6-dev-mips32 - GNU C Library: o32 Development Libraries for MIPS
 libc6-dev-mips64 - GNU C Library: 64bit Development Libraries for MIPS64
 libc6-dev-mipsn32 - GNU C Library: n32 Development Libraries for MIPS64
 libc6-dev-powerpc - GNU C Library: 32bit powerpc development libraries for ppc64
 libc6-dev-ppc64 - GNU C Library: 64bit Development Libraries for PowerPC64
 libc6-dev-s390 - GNU C Library: 32bit Development Libraries for IBM zSeries
 libc6-dev-sparc - GNU C Library: 32bit Development Libraries for SPARC
 libc6-dev-sparc64 - GNU C Library: 64bit Development Libraries for UltraSPARC
 libc6-dev-x32 - GNU C Library: X32 ABI Development Libraries for AMD64
 libc6-i386 - GNU C Library: 32-bit shared libraries for AMD64
 libc6-mips32 - GNU C Library: o32 Shared libraries for MIPS
 libc6-mips64 - GNU C Library: 64bit Shared libraries for MIPS64
 libc6-mipsn32 - GNU C Library: n32 Shared libraries for MIPS64
 libc6-pic  - GNU C Library: PIC archive library
 libc6-powerpc - GNU C Library: 32bit powerpc shared libraries for ppc64
 libc6-ppc64 - GNU C Library: 64bit Shared libraries for PowerPC64
 libc6-s390 - GNU C Library: 32bit Shared libraries for IBM zSeries
 libc6-sparc - GNU C Library: 32bit Shared libraries for SPARC
 libc6-sparc64 - GNU C Library: 64bit Shared libraries for UltraSPARC
 libc6-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc6-x32  - GNU C Library: X32 ABI Shared libraries for AMD64
 libc6-xen  - GNU C Library: Shared libraries [Xen version]
 libc6.1    - GNU C Library: Shared libraries
 libc6.1-alphaev67 - GNU C Library: Shared libraries (EV67 optimized)
 libc6.1-dbg - GNU C Library: detached debugging symbols
 libc6.1-dev - GNU C Library: Development Libraries and Header Files
 libc6.1-pic - GNU C Library: PIC archive library
 libc6.1-udeb - GNU C Library: Shared libraries - udeb (udeb)
 locales    - GNU C Library: National Language (locale) data [support]
 locales-all - GNU C Library: Precompiled locale data
 multiarch-support - Transitional package to ensure multiarch compatibility
 nscd       - GNU C Library: Name Service Cache Daemon
Closes: 879500 879501
Changes:
 glibc (2.26-0experimental0) experimental; urgency=medium
 .
   [ Adam Conrad ]
   * New upstream release (LP: #1703368), with git updates to 2017-10-10:
     - debian/{symbols.wildcards,control}: Update and regen for 2.26.
     - debian/patches/alpha/submitted-termios_h.diff: upstreamed.
     - debian/patches/arm/submitted-strip-bit-0.diff: upstreamed.
     - debian/patches/hurd-i386/git-__inet6_scopeid_pton.diff: upstreamed.
     - debian/patches/any/submitted-string2-strcmp.diff: obsolete.
     - debian/patches/any/local-tst-writev.diff: fixed upstream.
     - debian/patches/any/local-dynamic-resolvconf.diff: fixed upstream.
     - debian/patches/any/submitted-unicode-9.0.0.diff: obsolete.
     - debian/patches/any/cvs-malloc-hardening.diff: upstreamed.
     - debian/patches/any/local-bits-sigstack.diff: fixed upstream.
     - debian/patches/powerpc/submitted-tst-tlsopt-powerpc.diff: upstreamed.
     - debian/patches/i386/local-cmov.diff: dropped, no longer useful.
     - debian/patches/all/local-ldd.diff: rebased.
     - debian/patches/any/local-ldso-disable-hwcap.diff: rebased.
     - debian/patches/any/local-tcsetaddr.diff: rebased.
     - debian/patches/any/submitted-resolv-unaligned.diff: rebased.
     - debian/patches/arm/local-arm-futex.diff: rebased.
     - debian/patches/hurd-i386/local-ED.diff: rebased.
     - debian/patches/hurd-i386/tg-EGREGIOUS-fr.diff: rebased.
     - debian/patches/hurd-i386/tg-EIEIO-fr.diff: rebased.
     - debian/patches/kfreebsd/submitted-auxv.diff: rebased.
     - debian/patches/kfreebsd/submitted-waitid.diff: rebased.
     - debian/patches/localedata/locales-fr.diff: rebased.
     - debian/patches/sparc/submitted-sparc64-socketcall.diff: rebased.
     - debian/patches/localedata/local-hu_HU-sort.diff: Make testsuite
       agree with the sorting we see in Debian, may need another look.
     - debian/patches/any/local-cudacc-float128.diff: Local patch to prevent
       defining __HAVE_FLOAT128 on NVIDIA's CUDA compilers (LP: #1717257)
     - debian/patches/arm/git-arm64-memcmp.diff: Backport optimized memcmp
       for AArch64, improving performance from 25% to 500% (LP: #1720832)
     - debian/control.in/libc: Drop ancient Breaks satisfied in oldoldstable.
     - debian/{debhelper.in/libc.preinst,sysdeps/amd64.mk,sysdeps/i386.mk}:
       Bump MIN_KERNEL_SUPPORTED to 3.2 on x86, following upstream's change.
     - debian/sysdeps/{powerpc.mk,ppc64.mk,s390x.mk}: Disable lock-elision on
       powerpc and s390, following IBM's recommendation.
     - debian/testsuite-xfail-debian.mk: Re-enable xfailed resolv tests.
     - debian/testsuite-xfail-debian.mk: Allow tst-create-detached to fail on
       all platforms; the design of this test is such that the outcome relies
       on cache sizes and noisiness of the build system, which is unreliable.
     - debian/rules.d/build.mk: Configure with --enable-obsolete-nsl until we
       sort out a reasonable nsswitch migration strategy from compat to files.
 .
   [ Samuel Thibault ]
   * Adjust hurd-i386 patches to restore build and functionality with 2.26:
     - patches/hurd-i386/tg-gsync-libc.diff: rebased.
     - patches/hurd-i386/tg-hurdsig-global-dispositions.diff: rebased.
     - patches/hurd-i386/tg-pipe2.diff: rebased.
     - patches/hurd-i386/tg-socket_flags.diff: rebased.
     - patches/hurd-i386/tg2.25-tls.diff: rebased.
     - patches/hurd-i386/tg2.26-sched_param.diff: New patch.
     - patches/hurd-i386/git-sigsetops.h.diff: New patch.
     - patches/hurd-i386/git-sigsetops-2.h.diff: New patch.
     - patches/hurd-i386/git-sigsetops-3.h.diff: New patch.
     - patches/hurd-i386/tg2.26-sigsetops.h.diff: New patch.
     - patches/hurd-i386/git-bits_socket.h.diff: New patch.
     - patches/hurd-i386/git-preadwritev2.diff: New patch.
     - patches/hurd-i386/git-preadwritev2-2.diff: New patch.
     - patches/hurd-i386/git-preadwritev2-3.diff: New patch.
     - patches/hurd-i386/git-rtld-access.diff: New patch.
     - patches/hurd-i386/git-rtld-sbrk.diff: New patch.
     - patches/hurd-i386/git-rtld-sbrk-2.diff: New patch.
     - patches/hurd-i386/git-divdi.diff: New patch.
     - patches/hurd-i386/git-feraiseexcept.diff: New patch.
     - patches/hurd-i386/cvs-libpthread.diff: Update.
     - patches/hurd-i386/git-libpthread-2.26.diff: New patch.
     - patches/hurd-i386/git-i386-implies-x86.diff: New patch.
     - patches/hurd-i386/git-x86-tunables.diff: New patch.
     - patches/hurd-i386/git-rtld-strtoul_internal.diff: New patch.
     - patches/hurd-i386/git-clone.diff: New patch.
     - patches/hurd-i386/git-gethostname.diff: New patch.
     - patches/hurd-i386/cvs-libpthread-sigstate.diff: Remove unused merged
     patch.
     - patches/hurd-i386/cvs-send-recv-posix.diff: Remove unused merged patch.
     - patches/hurd-i386/cvs-truncate64.diff: Remove unused merged patch.
     - patches/hurd-i386/git-tst-udp-timeout.diff: New patch.
     - patches/hurd-i386/git-tst-udp-nonblocking.diff: New patch.
     - patches/hurd-i386/unsubmitted-exp-hidden-jump.diff: New patch.
     - patches/hurd-i386/git-hidden-def.diff: New patch.
     - patches/hurd-i386/git-hidden-def.diff-2: New patch.
     - patches/hurd-i386/git-dl-sysdep-check.diff: New patch.
     - patches/hurd-i386/git-socket-limit.diff: New patch.
     - patches/hurd-i386/tg-thread-linkspace.diff: New patch.
     - patches/hurd-i386/git-clock_gettime_gettimeofday.diff: New patch.
     - patches/hurd-i386/tg-gsync-libc.diff: Update.
     - patches/hurd-i386/tg-libpthread-gsync-mutex.diff: Update.
     - patches/hurd-i386/tg-sendmsg-SCM_CREDS.diff: Update.
     - patches/hurd-i386/git-sigsuspend_not_cancel.diff: New patch.
     - patches/hurd-i386/tg-sysvshm.diff: Update.
     - patches/hurd-i386/tg-ifaddrs_v6.diff: Update.
     - patches/hurd-i386/git-dirfd-linknamespace.diff: New patch.
     - patches/hurd-i386/git-revoke-linknamespace.diff: New patch.
     - patches/hurd-i386/git-seekdir-linknamespace.diff: New patch.
     - patches/hurd-i386/git-ifaddrs-linknamespace.diff: New patch.
     - patches/hurd-i386/git-NO_HIDDEN.diff: New patch.
     - patches/hurd-i386/unsubmitted-NO_HIDDEN.diff: Remove patch.
     - patches/hurd-i386/unsubmitted-exp-hidden-jump.diff: Remove patch.
     - testsuite-xfail-debian.mk: Update.
     - testsuite-xfail-debian.mk: Remove now-removed XPG3 entries.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
     - Fix buffer overflow in glob with GLOB_TILDE (CVE-2017-15670).  Closes:
       #879501.
     - Fix memory leak in glob with GLOB_TILDE (CVE-2017-15671).  Closes:
       #879500.
   * debian/rules, debian/control.in/main: build with GCC 7.
   * debian/testsuite-xfail-debian.mk: remove a few XFAIL on s390x that were
     due to GCC 6 issues.
   * debian/testsuite-xfail-debian.mk: drop support for s390.
   * debian/testsuite-xfail-debian.mk: Use granular fma XFAIL on mips*.
   * debian/testsuite-xfail-debian.mk: mark misc/tst-set_ppr as XFAIL on
     powerpc as it requires a recent CPU or a recent kernel for CPU feature
     detection.
   * debian/patches/any/local-libgcc-compat-{abilists,main,ports}.diff: drop
     workaround for binaries built with some broken versions of GCC 3.2 more
     than 10 years ago.
   * debian/testsuite-xfail-debian.mk: remove many XFAIL from mips, mipsel and
     mips64el.
Checksums-Sha1:
 1e18de8b86b6ecc4791b62ac11e225a79da1ec31 8241 glibc_2.26-0experimental0.dsc
 3e7cab60063b32c1eb15e71065e3380e81d29222 15270760 glibc_2.26.orig.tar.xz
 5027e213fa408bdb8f82e536e5d31a45bc47614a 1053392 glibc_2.26-0experimental0.debian.tar.xz
 a198dffb282480a700f9a7bb81c1d8256ec70c47 7507 glibc_2.26-0experimental0_source.buildinfo
Checksums-Sha256:
 ccdca9afc387175c29f379f577de334c694a4624340c14d6f4142063a1be246d 8241 glibc_2.26-0experimental0.dsc
 38afc835050aa0850fbe15b10a7b18b7c1c70dc5a2fdf980762f3ad49e771870 15270760 glibc_2.26.orig.tar.xz
 5c0b0fd2909d3b96728ec2f2c2dfd8b82803bcf55a4727ac1869a6feca21eed0 1053392 glibc_2.26-0experimental0.debian.tar.xz
 feb0d6e6dcaea6fe2305346de77dd8f2867dde9e3c1c882a56b3420532e0b113 7507 glibc_2.26-0experimental0_source.buildinfo
Files:
 24984ce7e27a948453e34e59446aab40 8241 libs required glibc_2.26-0experimental0.dsc
 666ae66c12aeedd26a3a4c550ee79eaf 15270760 libs required glibc_2.26.orig.tar.xz
 9173ae85f2d5af45d0dbe020007c9507 1053392 libs required glibc_2.26-0experimental0.debian.tar.xz
 1ac44d995509e0e76dd006e8a6d7a5f2 7507 libs required glibc_2.26-0experimental0_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEd0YmQqnvlP0Pdxltupx4Bh3djJsFAloRcL0ACgkQupx4Bh3d
jJsDORAAuGa3frswNKfHZIkSLgTnNrhE4NZ6+Y2gg5WIhVHNFmQwf+ub4zLQzwFD
EJmpzZDnVerTw9+74EPXzTxJgaIW/0YiP93tPGAMLR19v/5FkQUvCYmlCX/T/aTc
clb0UkBLbVfQrdslimp+fKoBJ+ulInbjBhKkz2TiPWqQcfNFAIyH1+awydmZ6G+t
jANNH75SrTSYwNmP8zz5PiFLRSx9Aau0M18oqG7Y/tbv9PiJ0TXzvLICHdOZAZDV
7e36ep+/J0c7RDhwQhHDs2Govy4EdSyG6oah6XFbqq/MkPn4tLAC7LtzzR3IbwQG
8Q2Z6zvGIcJS6cNLZd+s2O404O5Mprah93mP07+ZvzKcDujpiM5HERDUeQ+jV5pJ
BNE7Da5TL8DheyrSpzomhjrcnY66sWBq7LSmYbdIkURnHpHB1+jthqzlB2N6FnfC
X7r/G44FCVWKJeBwJux4Gjs5jaJ3qp2cAT5haaflWVYxGLgKb5fEMNbmn19hLteS
BBmyA0lNl7l6mJPVkSPhZ7w0VOyLUU2/KhXuakVvBOId5pepafj2WRmu+HGuxx31
e79y7yNCmHz2Iw2BJSU3eHy/VW3IpPkOl9Jk6mmvuHjVysSIwOVhl5eSGPW+uYoK
jLkRCNQUoSiEOmLd1gxMQJ4FH4WoGe5g8x3cBeU9yriVV32kr8s=
=/i8d
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: