Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1130755 > unrolled thread

Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption

Started by"Steinar H. Gunderson" <sesse@debian.org>
First post2022-12-30 12:00 +0100
Last post2022-12-30 19:10 +0100
Articles 5 — 3 participants

Back to article view | Back to linux.debian.bugs.dist

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption "Steinar H. Gunderson" <sesse@debian.org> - 2022-12-30 12:00 +0100
    Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Tobias Frost <tobi@debian.org> - 2022-12-30 12:10 +0100
      Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Tobias Frost <tobi@debian.org> - 2022-12-30 12:40 +0100
      Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption "Steinar H. Gunderson" <sesse@debian.org> - 2022-12-30 12:40 +0100
      Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Salvatore Bonaccorso <carnil@debian.org> - 2022-12-30 19:10 +0100

#1130755 — Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption

From"Steinar H. Gunderson" <sesse@debian.org>
Date2022-12-30 12:00 +0100
SubjectBug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption
Message-ID<FIlhf-ejel-3@gated-at.bofh.it>
On Fri, Dec 30, 2022 at 11:04:46AM +0100, Tobias Frost wrote:
> I was trying to triage this CVE and *maybe* those revisions are related:
> 
> r1894937 ("apreq_parse_headers: Discard CRLF of folded values.")
> r1894940 ("reindent (no functional change).") 
> r1894977 ("Follow up to r1894937: Fix setting of empty value.")
> r1895054 ("Follow up to r1894937: Always eat CRLF at the end of header value.")

Perhaps it's best to remove libapreq2 entirely? I don't use nor maintain it
anymore, it's been out of testing for a while, and there's this CVE.

/* Steinar */
-- 
Homepage: https://www.sesse.net/

[toc] | [next] | [standalone]


#1130760

FromTobias Frost <tobi@debian.org>
Date2022-12-30 12:10 +0100
Message-ID<FIlqV-ejxf-3@gated-at.bofh.it>
In reply to#1130755

[Multipart message — attachments visible in raw view] — view raw

On Fri, Dec 30, 2022 at 11:18:14AM +0100, Steinar H. Gunderson wrote:
> On Fri, Dec 30, 2022 at 11:04:46AM +0100, Tobias Frost wrote:
> > I was trying to triage this CVE and *maybe* those revisions are related:
> > 
> > r1894937 ("apreq_parse_headers: Discard CRLF of folded values.")
> > r1894940 ("reindent (no functional change).") 
> > r1894977 ("Follow up to r1894937: Fix setting of empty value.")
> > r1895054 ("Follow up to r1894937: Always eat CRLF at the end of header value.")
> 
> Perhaps it's best to remove libapreq2 entirely? I don't use nor maintain it
> anymore, it's been out of testing for a while, and there's this CVE.

#ssh mirror.ftp-master.debian.org "dak rm -Rn libapreq2"

	Will remove the following packages from unstable:

	libapache2-mod-apreq2 |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
	libapache2-request-perl |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
	 libapreq2 |     2.13-7 | source
	libapreq2-3 |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
	libapreq2-dev |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
	libapreq2-doc |     2.13-7 | all

	Maintainer: Steinar H. Gunderson <sesse@debian.org>

	------------------- Reason -------------------

	----------------------------------------------

	Checking reverse dependencies...
	# Broken Depends:
	libapache2-authcassimple-perl: libapache2-authcassimple-perl
	libapache2-sitecontrol-perl: libapache2-sitecontrol-perl
	lua-apr: lua-apr
	rapache: libapache2-mod-r-base

	# Broken Build-Depends:
	libapache2-sitecontrol-perl: libapache2-request-perl
	lua-apr: libapreq2-dev
	rapache: libapreq2-dev

	Dependency problem found.

... and still theres a need to fix the CVE for stable (and also for (E)LTS)

(I'm currently take a look at 2.17, to see if I can get it packages, if I'm succeeding,
there will be an NMU announcement :))

> /* Steinar */
> -- 
> Homepage: https://www.sesse.net/

[toc] | [prev] | [next] | [standalone]


#1130765

FromTobias Frost <tobi@debian.org>
Date2022-12-30 12:40 +0100
Message-ID<FIlTX-ejGD-1@gated-at.bofh.it>
In reply to#1130760
On Fri, Dec 30, 2022 at 12:28:49PM +0100, Steinar H. Gunderson wrote:
> On Fri, Dec 30, 2022 at 12:04:29PM +0100, Tobias Frost wrote:
> > (I'm currently take a look at 2.17, to see if I can get it packages, if I'm succeeding,
> > there will be an NMU announcement :))
> 
> If you are NMUing, could you orphan the package in the upload?

Yes, will do that.

> /* Steinar */
> -- 
> Homepage: https://www.sesse.net/

[toc] | [prev] | [next] | [standalone]


#1130767

From"Steinar H. Gunderson" <sesse@debian.org>
Date2022-12-30 12:40 +0100
Message-ID<FIlTX-ejGD-3@gated-at.bofh.it>
In reply to#1130760
On Fri, Dec 30, 2022 at 12:04:29PM +0100, Tobias Frost wrote:
> (I'm currently take a look at 2.17, to see if I can get it packages, if I'm succeeding,
> there will be an NMU announcement :))

If you are NMUing, could you orphan the package in the upload?

/* Steinar */
-- 
Homepage: https://www.sesse.net/

[toc] | [prev] | [next] | [standalone]


#1130841

FromSalvatore Bonaccorso <carnil@debian.org>
Date2022-12-30 19:10 +0100
Message-ID<FIrZp-enKS-49@gated-at.bofh.it>
In reply to#1130760
Hi,

On Fri, Dec 30, 2022 at 05:25:41PM +0100, Tobias Frost wrote:
> On Fri, Dec 30, 2022 at 04:14:25PM +0100, Salvatore Bonaccorso wrote:
> > Hi Steinar, hi Tobias,
> > 
> > On Fri, Dec 30, 2022 at 12:04:29PM +0100, Tobias Frost wrote:
> > > On Fri, Dec 30, 2022 at 11:18:14AM +0100, Steinar H. Gunderson wrote:
> > > > On Fri, Dec 30, 2022 at 11:04:46AM +0100, Tobias Frost wrote:
> > > > > I was trying to triage this CVE and *maybe* those revisions are related:
> > > > > 
> > > > > r1894937 ("apreq_parse_headers: Discard CRLF of folded values.")
> > > > > r1894940 ("reindent (no functional change).") 
> > > > > r1894977 ("Follow up to r1894937: Fix setting of empty value.")
> > > > > r1895054 ("Follow up to r1894937: Always eat CRLF at the end of header value.")
> > > > 
> > > > Perhaps it's best to remove libapreq2 entirely? I don't use nor maintain it
> > > > anymore, it's been out of testing for a while, and there's this CVE.
> > > 
> > > #ssh mirror.ftp-master.debian.org "dak rm -Rn libapreq2"
> > > 
> > > 	Will remove the following packages from unstable:
> > > 
> > > 	libapache2-mod-apreq2 |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
> > > 	libapache2-request-perl |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
> > > 	 libapreq2 |     2.13-7 | source
> > > 	libapreq2-3 |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
> > > 	libapreq2-dev |  2.13-7+b4 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x
> > > 	libapreq2-doc |     2.13-7 | all
> > > 
> > > 	Maintainer: Steinar H. Gunderson <sesse@debian.org>
> > > 
> > > 	------------------- Reason -------------------
> > > 
> > > 	----------------------------------------------
> > > 
> > > 	Checking reverse dependencies...
> > > 	# Broken Depends:
> > > 	libapache2-authcassimple-perl: libapache2-authcassimple-perl
> > > 	libapache2-sitecontrol-perl: libapache2-sitecontrol-perl
> > > 	lua-apr: lua-apr
> > > 	rapache: libapache2-mod-r-base
> > > 
> > > 	# Broken Build-Depends:
> > > 	libapache2-sitecontrol-perl: libapache2-request-perl
> > > 	lua-apr: libapreq2-dev
> > > 	rapache: libapreq2-dev
> > > 
> > > 	Dependency problem found.
> > > 
> > > ... and still theres a need to fix the CVE for stable (and also for (E)LTS)
> > > 
> > > (I'm currently take a look at 2.17, to see if I can get it packages, if I'm succeeding,
> > > there will be an NMU announcement :))
> > 
> > Upstream has still not clarified on
> > https://www.openwall.com/lists/oss-security/2022/08/26/4 and given it
> > was now out of bookworm, it might be wise that we actually sunset it
> > for bookworm (including having the above reverse dependencies out of
> > bookworm).
> > 
> > Fixing stable and oldstable is then another story, and I still hope we
> > get feedback from upstream on pinpointing the fixes.
> 
> ACK, I will file a "not suitable for bookworm" bug, so that the new package and r-depends won't migrate.

Thank you Tobi!

> Lets hope that upstream answers…

Regards,
Salvatore

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web