<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>7258</bug_id>
          
          <creation_ts>2015-01-28 07:13:24 +0000</creation_ts>
          <short_desc>glibc: __nss_hostname_digits_dots() heap-based buffer overflow (CVE-2015-0235)</short_desc>
          <delta_ts>2015-01-28 12:13:06 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Undecided</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sona Sarmadi">sona.sarmadi</reporter>
          <assigned_to name="Saul Wold">sgw</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>48353</commentid>
    <comment_count>0</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-01-28 07:13:24 +0000</bug_when>
    <thetext>A heap overflow in glibc&apos;s gethostbyname() function.

This is redhat&apos;s report:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0235


Upstream patch:

https://sourceware.org/git/?p=glibc.git;a=commit;h=d5dd6189d506068ed11c8bfa1e1e9bffde04decd


This seems to be a reported from qualys, here is &quot;Qualys Security Advisory CVE-2015-0235 - GHOST: glibc gethostbyname&quot;

http://www.openwall.com/lists/oss-security/2015/01/27/9</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>48360</commentid>
    <comment_count>1</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-01-28 12:13:06 +0000</bug_when>
    <thetext>From yocto mailing list:

&gt; On 28 January 2015 at 11:17, Damian, Alexandru 
&gt; &lt;alexandru.damian@intel.com&gt;
&gt; wrote:
&gt; &gt; Do we need to open a bug to track this ?
&gt; 
&gt; Probably for the best to ensure it goes into all the branches we support.

FYI, none of the branches we still officially support use (e)glibc older than 2.18, which is where the fix went in upstream; even dora that just went out of support has 2.18 as the default (2.17 is included though).

Cheers,
Paul

Closing this issue now since this does not affects us!!</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>