Bug 1050380 (CVE-2017-11608) - VUL-1: libsass: Heap based buffer overflow
Summary: VUL-1: libsass: Heap based buffer overflow
Status: RESOLVED FIXED
Alias: CVE-2017-11608
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.2
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/189071/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-07-25 09:42 UTC by Johannes Segitz
Modified: 2017-11-07 07:35 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
Reproducer (5 bytes, application/octet-stream)
2017-07-25 09:42 UTC, Johannes Segitz
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2017-07-25 09:42:51 UTC
Created attachment 733701 [details]
Reproducer

rh#1474276

There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak
function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote
denial of service attack.

valgrind sassc POC

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1474276
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-11608
http://www.cvedetails.com/cve/CVE-2017-11608/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11608
Comment 1 Cédric Bosdonnat 2017-10-26 11:56:08 UTC
Here is the valgrind output with 3.4.6:
valgrind ./sassc POC 
==32611== Memcheck, a memory error detector
==32611== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al.
==32611== Using Valgrind-3.12.0 and LibVEX; rerun with -h for copyright info
==32611== Command: ./sassc /home/cbosdo/Downloads/POC
==32611== 
Internal Error: Invalid UTF-8
==32611== 
==32611== HEAP SUMMARY:
==32611==     in use at exit: 0 bytes in 0 blocks
==32611==   total heap usage: 576 allocs, 576 frees, 120,001 bytes allocated
==32611== 
==32611== All heap blocks were freed -- no leaks are possible
==32611== 
==32611== For counts of detected and suppressed errors, rerun with: -v
==32611== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0)

Looks like the issue has been fixed between 3.4.3 and 3.4.6. SR is on its way to Factory.
Comment 2 Cédric Bosdonnat 2017-10-26 15:59:41 UTC
After git bisect fun, it seems the commit fixing that is https://github.com/sass/libsass/commit/648f763ede97f9a2c2c843a0a18ac18bbde3507b
Comment 3 Cédric Bosdonnat 2017-10-27 12:17:16 UTC
Fixed some of the errors. SR sent: https://build.opensuse.org/request/show/537069
Comment 4 Andreas Stieger 2017-11-07 01:01:23 UTC
release for Leap, done
Comment 5 Swamp Workflow Management 2017-11-07 05:11:37 UTC
openSUSE-SU-2017:2939-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1050148,1050149,1050150,1050151,1050380
CVE References: CVE-2017-11554,CVE-2017-11555,CVE-2017-11556,CVE-2017-11605,CVE-2017-11608
Sources used:
openSUSE Leap 42.3 (src):    libsass-3.3.2-5.1
openSUSE Leap 42.2 (src):    libsass-3.3.2-2.3.1