Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 47 (release-18.09) #47122

Closed
28 of 78 tasks
ckauhaus opened this issue Sep 21, 2018 · 21 comments
Closed
28 of 78 tasks

Vulnerability roundup 47 (release-18.09) #47122

ckauhaus opened this issue Sep 21, 2018 · 21 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Sep 21, 2018

Scanned nixos/release-combined.nix @ ef450ef. Filtered out previously reported CVEs. May contain false positives.

binutils-2.30 (search, files)

coreutils-8.29 (search, files)

exempi-2.4.5 (search, files)

ffmpeg-3.4.4 (search, files)

glibc-2.27 (search, files)

graphviz-2.40.1 (search, files)

gstreamer-0.10.36 (search, files)

jasper-2.0.14 (search, files)

jquery-ui-1.11.4 (search, files)

libarchive-3.3.2 (search, files)

libcroco-0.6.12 (search, files)

libid3tag-0.15.1b (search, files)

libmad-0.15.1b (search, files)

libsass-3.5.4 (search, files)

libsndfile-1.0.28 (search, files)

libtiff-4.0.9 (search, files)

libvorbis-1.3.6 (search, files)

lua-5.1.5 (search, files)

net-snmp-5.7.3 (search, files)

openjpeg-2.3.0 (search, files)

patch-2.7.6 (search, files)

procps-3.3.15 (search, files)

rsync-3.1.3 (search, files)

sddm-0.17.0 (search, files)

taglib-1.11.1 (search, files)

wildmidi-0.4.2 (search, files)

wpa_supplicant-2.6 (search, files)

zip-3.0 (search, files)

Cc: @joepie91, @phanimahesh, @the-kenny, @7c6f434c, @k0001, @peterhoeg, @nh2, @LnL7, @grahamc, @adisbladis, @fpletz, @vcunat

Contact @ckauhaus for any questions.

@ckauhaus
Copy link
Contributor Author

master is #47121

ckauhaus pushed a commit to ckauhaus/nixpkgs that referenced this issue Sep 21, 2018
Both versions are not maintained anymore upstream and have open security
issues, e.g. https://nvd.nist.gov/vuln/detail/CVE-2014-5461.

The same holds for lua5_1 but that seems to be in use in some places.

Re NixOS#47122
Re NixOS#47123
@vcunat vcunat added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Sep 23, 2018
@vcunat
Copy link
Member

vcunat commented Sep 23, 2018

coreutils: @ckauhaus can you whitelist this CVE? See #38993 (comment)

@ckauhaus
Copy link
Contributor Author

@vcunat each CVE is reoprted only once per branch anyway

@periklis
Copy link
Contributor

@ckauhaus exempi was patched in master by @Ma27 and i see it is merged in release-18.09 branch (See L12)

@periklis
Copy link
Contributor

@ckauhaus i've checked our release-18.09 channel for lua and the patch is included. (See L23)

@periklis
Copy link
Contributor

According to RH-Errata (https://access.redhat.com/errata/RHSA-2016:2974) the gstreamer issue affects only the package gstreamer-plugins-bad and the affected plugin was removed in 0.10.19. We have actually 1.14.2 in release-18.09 and master. I've checked the source files and the NSF plugin is not listed anymore.

@periklis
Copy link
Contributor

For jquery-ui there is an new release 1.12.1 which includes the patch :
jquery/jquery-ui@1-11-stable...1.12

How important is nixos/lib/testing?

@periklis
Copy link
Contributor

periklis commented Oct 28, 2018

For libarchive-3.3.2:

@periklis
Copy link
Contributor

For libid3tag a patch is available in bugzilla. According to debian both CVEs point to the same issue. Thus the patch should solve both.

@ckauhaus
Copy link
Contributor Author

@periklis great job, thanks :)

One request: please tick off the pkgs that you have been reviewed in the list at the top.

@ckauhaus
Copy link
Contributor Author

For jquery-ui there is an new release 1.12.1 which includes the patch :
jquery/[email protected]
How important is `nixos/lib/testing?

Didn't get it - do you mean that the vuln is exploitable via a nixos test?

@ckauhaus
Copy link
Contributor Author

@periklis Would it be feasible to provide PRs for both libarchive and libid3tag?

@periklis
Copy link
Contributor

periklis commented Nov 1, 2018

@ckauhaus I will provide PRs for both libarchive and libid3tag in the next days.

As for jquery-ui, sinse is used only for nixos-testing, i am not sure if we should patch by updating. wdyt?

@periklis
Copy link
Contributor

periklis commented Nov 1, 2018

@ckauhaus unfortunately i cannot tick the items in the list at the top.

@fpletz
Copy link
Member

fpletz commented Nov 1, 2018

The wpa_supplicant CVEs have already been fixed last year: ea50efc

@fpletz
Copy link
Member

fpletz commented Nov 1, 2018

We're not affected by CVE-2014-2285 for net_snmp because we have the fixed version (fixed in >= 5.7.3_pre3 and we have 5.7.3) and our version of perl is new enough to be unaffected anyway (same for RHEL as in https://bugzilla.redhat.com/show_bug.cgi?id=1072778).

@fpletz
Copy link
Member

fpletz commented Nov 1, 2018

CVE-2018-7263 in libmad is a duplicate of CVE-2017-11552 for libao. Doesn't seem to be fixed upstream and doesn't look to be reproducible. Not actionable for now.

@c0bw3b
Copy link
Contributor

c0bw3b commented Dec 8, 2018

CVE-2017-17480 fixed in b3aff3a

@vcunat
Copy link
Member

vcunat commented Mar 10, 2019

rsync CVE-2017-16548: see #38993 (comment)

@vcunat
Copy link
Member

vcunat commented Mar 10, 2019

@Ekleog
Copy link
Member

Ekleog commented Jun 29, 2019

Closing as 18.09 is no longer supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

6 participants