Bug 1019036 (CVE-2016-10128)

Summary: VUL-0: CVE-2016-10128,CVE-2016-10129: libgit2: edge cases in the Git Smart Protocol can lead to attempting to parse outside of the buffer
Product: [Novell Products] SUSE Security Incidents Reporter: Andreas Stieger <astieger>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: dimstar, hpj, meissner, sreeves
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard: CVSSv2:SUSE:CVE-2016-10128:5.8:(AV:N/AC:M/Au:N/C:P/I:N/A:P) CVSSv2:SUSE:CVE-2016-10129:6.8:(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Swamp Workflow Management 2017-01-10 23:00:35 UTC
bugbot adjusting priority
Comment 3 Andreas Stieger 2017-01-11 10:07:59 UTC
HPJ are these for you?
Comment 4 Andreas Stieger 2017-01-11 10:20:57 UTC
For openSUSE, requesting fixes for:

openSUSE:13.2:Update/libgit2 (*couple of days left on maintenance)
openSUSE:Leap:42.1:Update/libgit2

openSUSE:Backports:SLE-12-SP1/libgit2 (just submit 0.24.6 from devel:libraries:c_c++ once https://build.opensuse.org/request/show/449627 does through)

Please include bug 1003810.

Rest is done via SLE maintenance.
Comment 6 Scott Reeves 2017-01-31 00:03:55 UTC
SLE12-SP2 - IBS SR#127382
Leap 42.1 - OBS SR#453542
openSUSE:Backports:SLE-12-SP1 - OBS SR#453540

Leap42.2 will populate from SLE12 submission and 13.2 is out of support and not returned by a mbranch checkout.

Assigning back to security team...
Comment 7 Bernhard Wiedemann 2017-01-31 01:00:58 UTC
This is an autogenerated message for OBS integration:
This bug (1019036) was mentioned in
https://build.opensuse.org/request/show/453540 Backports:SLE-12-SP1 / libgit2
https://build.opensuse.org/request/show/453542 42.1 / libgit2
Comment 8 Swamp Workflow Management 2017-02-06 14:12:36 UTC
openSUSE-SU-2017:0397-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1019036,1019037
CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339
Sources used:
openSUSE Leap 42.1 (src):    libgit2-0.22.1-8.1
Comment 9 Swamp Workflow Management 2017-02-06 17:09:32 UTC
openSUSE-SU-2017:0405-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1019036,1019037
CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    libgit2-0.24.6-10.1
Comment 10 Marcus Meissner 2017-02-09 10:18:54 UTC
released
Comment 11 Swamp Workflow Management 2017-02-09 14:12:04 UTC
SUSE-SU-2017:0433-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1019036,1019037
CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    libgit2-0.24.1-6.1
Comment 12 Swamp Workflow Management 2017-02-17 03:16:01 UTC
openSUSE-SU-2017:0484-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1019036,1019037
CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339
Sources used:
openSUSE Leap 42.2 (src):    libgit2-0.24.1-6.1