Bug 10617 - curl: multiple CVEs; CVE-2016-8615 /25
Summary: curl: multiple CVEs; CVE-2016-8615 /25
Status: RESOLVED FIXED
Alias: None
Product: Security - Recipe Upgrade
Classification: Build System, Metadata & Runtime
Component: security (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Undecided normal
Target Milestone: ---
Assignee: Saul Wold
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-11-08 07:49 UTC by Sona Sarmadi
Modified: 2018-02-01 15:52 UTC (History)
2 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sona Sarmadi 2016-11-08 07:49:32 UTC
Multiple CVEs were reported in curl:

cookie injection for other servers
CVE-2016-8615

case insensitive password comparison
CVE-2016-8616

OOB write via unchecked multiplication
CVE-2016-8617

double-free in curl_maprintf
CVE-2016-8618

double-free in krb5 code
CVE-2016-8619

glob parser write/read out of bounds
CVE-2016-8620

curl_getdate read out of bounds
CVE-2016-8621

URL unescape heap overflow via integer truncation
CVE-2016-8622

Use-after-free via shared cookies
CVE-2016-8623

invalid URL parsing with '#'
CVE-2016-8624

IDNA 2003 makes curl use wrong host
CVE-2016-8625

For more info see 
https://curl.haxx.se/docs/security.html 

All branches seems to be affected.
Comment 1 Sona Sarmadi 2016-11-08 11:30:39 UTC
Patch sent to master:
https://patchwork.openembedded.org/patch/133682/

I will send patches to morty & krogoth soon.
Comment 2 Sona Sarmadi 2016-11-09 09:30:04 UTC
curl 7.51.0-r0 address all these CVEs. A patch for master has been sent to upgrade curl to 7.51.0-r0. I wonder if we can upgrade krogoth and morty to 7.51.0-r0 as well? Both package versions are using same libcurl.so version i.e. libcurl.so.4.4.0:

tmp/work/i586-poky-linux/curl/7.47.1-r0/sysroot-destdir/usr/lib/libcurl.so.4.4.0
tmp/work/i586-poky-linux/curl/7.51.0-r0/sysroot-destdir/usr/lib/libcurl.so.4.4.0
Comment 3 Sona Sarmadi 2016-11-11 11:31:38 UTC
Patch sent to master is applicable for morty branch as well.

Patches sent for krogoth.
Comment 4 Armin Kuster 2018-02-01 15:50:12 UTC
in krogoth.
Comment 6 Richard Purdie 2018-02-01 15:52:10 UTC
http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=morty&id=6131edc2c9de3d2fe03243a423e2441a6ec855ce and preceeding commits, so all maintained stable branches are fixed.