Bug 1002982 - (CVE-2016-7969) VUL-0: CVE-2016-7969, CVE-2016-7970, CVE-2016-7971, CVE-2016-7972: libass: multiple memory management issues
(CVE-2016-7969)
VUL-0: CVE-2016-7969, CVE-2016-7970, CVE-2016-7971, CVE-2016-7972: libass: mu...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/173155/
CVSSv2:SUSE:CVE-2016-7971:5.1:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-10-05 08:04 UTC by Johannes Segitz
Modified: 2017-10-26 07:20 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Tomáš Chvátal 2016-10-05 08:49:18 UTC
Oky, lets wait for the 2nd CVE then I put the latest version to factory at least for now.

Also it seems like they don't plan to fix the DOS issue anytime soon given the comments?
Comment 2 Bernhard Wiedemann 2016-10-05 10:01:26 UTC
This is an autogenerated message for OBS integration:
This bug (1002982) was mentioned in
https://build.opensuse.org/request/show/433292 13.2 / libass
https://build.opensuse.org/request/show/433294 42.1 / libass
https://build.opensuse.org/request/show/433295 42.2 / libass
https://build.opensuse.org/request/show/433296 Factory / libass
Comment 3 Bernhard Wiedemann 2016-10-05 14:01:21 UTC
This is an autogenerated message for OBS integration:
This bug (1002982) was mentioned in
https://build.opensuse.org/request/show/433343 42.2 / libass
Comment 4 Swamp Workflow Management 2016-10-05 22:00:38 UTC
bugbot adjusting priority
Comment 5 Bernhard Wiedemann 2016-10-07 20:00:57 UTC
This is an autogenerated message for OBS integration:
This bug (1002982) was mentioned in
https://build.opensuse.org/request/show/433791 Factory / libass
Comment 6 Tomáš Chvátal 2016-10-13 10:34:22 UTC
Also we have in there:
 * Fix illegal read in Gaussian blur coefficient calculations. (CVE-2016-7970)

Still no fix for 7971.
Comment 7 Andreas Stieger 2016-11-22 12:16:29 UTC
(In reply to Tomáš Chvátal from comment #6)
> Also we have in there:
>  * Fix illegal read in Gaussian blur coefficient calculations.
> (CVE-2016-7970)

https://github.com/libass/libass/commit/08e754612019ed84d1db0d1fc4f5798248decd75

fixed in 0.13.4

> Still no fix for 7971.

Regarding CVE-2016-7971, from http://seclists.org/oss-sec/2016/q4/299

> The MITRE CVE team has no current plans to reject this CVE.
> [...]
> Even if neither the upstream vendor nor any Linux distribution will
> ever make any code change for CVE-2016-7971, discussion of the issue
> can help with understanding the product's behavior.
> [...]
> The MITRE CVE team is willing to mark a CVE with "DISPUTED" if someone
> believes that it's based solely on an "AddressSanitizer failed to
> allocate ... bytes of LargeMmapAllocator" misinterpretation, and
> believes that it cannot have any relevance to risk management.

Not fixing CVE-2016-7971: Does not really affect us, not using ASAN.
Comment 8 Bernhard Wiedemann 2016-12-04 11:00:27 UTC
This is an autogenerated message for OBS integration:
This bug (1002982) was mentioned in
https://build.opensuse.org/request/show/443692 42.1 / libass
https://build.opensuse.org/request/show/443693 13.2 / libass
Comment 9 Tomáš Chvátal 2016-12-04 11:10:48 UTC
All submissions done with CVE's as applicable for various codestreams.
Comment 11 Swamp Workflow Management 2016-12-12 17:08:24 UTC
openSUSE-SU-2016:3087-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1002982
CVE References: CVE-2016-7969,CVE-2016-7972
Sources used:
openSUSE Leap 42.1 (src):    libass-0.12.3-6.1
openSUSE 13.2 (src):    libass-0.12.1-2.8.1
Comment 12 Swamp Workflow Management 2016-12-13 12:10:22 UTC
SUSE-SU-2016:3107-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1002982
CVE References: CVE-2016-7969,CVE-2016-7970,CVE-2016-7971,CVE-2016-7972
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    libass-0.10.2-3.1
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    libass-0.10.2-3.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    libass-0.10.2-3.1
SUSE Linux Enterprise Server 12-SP2 (src):    libass-0.10.2-3.1
SUSE Linux Enterprise Server 12-SP1 (src):    libass-0.10.2-3.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    libass-0.10.2-3.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    libass-0.10.2-3.1
Comment 13 Marcus Meissner 2017-10-26 07:20:58 UTC
released