Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.rc > #356054 > unrolled thread

Bug#1063484: libuv1: CVE-2024-24806

Started bySalvatore Bonaccorso <carnil@debian.org>
First post2024-02-08 21:00 +0100
Last post2024-03-18 23:10 +0100
Articles 9 — 3 participants

Back to article view | Back to linux.debian.bugs.rc


Contents

  Bug#1063484: libuv1: CVE-2024-24806 Salvatore Bonaccorso <carnil@debian.org> - 2024-02-08 21:00 +0100
    Bug#1063484: libuv1: CVE-2024-24806 Dominique Dumont <dod@debian.org> - 2024-02-14 13:10 +0100
      Bug#1063484: libuv1: CVE-2024-24806 Dominique Dumont <dod@debian.org> - 2024-02-20 19:20 +0100
        Bug#1063484: libuv1: CVE-2024-24806 Salvatore Bonaccorso <carnil@debian.org> - 2024-02-29 22:00 +0100
    Bug#1063484: marked as done (libuv1: CVE-2024-24806) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-02-19 09:00 +0100
    Bug#1063484: libuv1: CVE-2024-24806 Salvatore Bonaccorso <carnil@debian.org> - 2024-03-06 21:10 +0100
    Bug#1063484: libuv1: CVE-2024-24806 Salvatore Bonaccorso <carnil@debian.org> - 2024-03-10 15:00 +0100
    Bug#1063484: marked as done (libuv1: CVE-2024-24806) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-03-17 18:10 +0100
    Bug#1063484: marked as done (libuv1: CVE-2024-24806) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-03-18 23:10 +0100

#356054 — Bug#1063484: libuv1: CVE-2024-24806

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-02-08 21:00 +0100
SubjectBug#1063484: libuv1: CVE-2024-24806
Message-ID<I5iIV-8NST-1@gated-at.bofh.it>
Source: libuv1
Version: 1.46.0-3
Severity: grave
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for libuv1.

CVE-2024-24806[0]:
| libuv is a multi-platform support library with a focus on
| asynchronous I/O. The `uv_getaddrinfo` function in
| `src/unix/getaddrinfo.c` (and its windows counterpart
| `src/win/getaddrinfo.c`), truncates hostnames to 256 characters
| before calling `getaddrinfo`. This behavior can be exploited to
| create addresses like `0x00007f000001`, which are considered valid
| by `getaddrinfo` and could allow an attacker to craft payloads that
| resolve to unintended IP addresses, bypassing developer checks. The
| vulnerability arises due to how the `hostname_ascii` variable (with
| a length of 256 bytes) is handled in `uv_getaddrinfo` and
| subsequently in `uv__idna_toascii`. When the hostname exceeds 256
| characters, it gets truncated without a terminating null byte. As a
| result attackers may be able to access internal APIs or for websites
| (similar to MySpace) that allows users to have
| `username.example.com` pages. Internal services that crawl or cache
| these user pages can be exposed to SSRF attacks if a malicious user
| chooses a long vulnerable username. This issue has been addressed in
| release version 1.48.0. Users are advised to upgrade. There are no
| known workarounds for this vulnerability.

Note, that the advisory at [1] mentions that affected versions are
only > 1.45.x. Looking at the git changes, is it not introduced after
6dd44caa35b4 ("unix,win: support IDNA 2008 in uv_getaddrinfo()") in
v1.24.0?

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-24806
    https://www.cve.org/CVERecord?id=CVE-2024-24806
[1] https://github.com/libuv/libuv/security/advisories/GHSA-f74f-cvh7-c6q6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

[toc] | [next] | [standalone]


#356357

FromDominique Dumont <dod@debian.org>
Date2024-02-14 13:10 +0100
Message-ID<I7mfn-a5QJ-9@gated-at.bofh.it>
In reply to#356054
On Thu, 08 Feb 2024 20:51:30 +0100 Salvatore Bonaccorso <carnil@debian.org> 
wrote:
> Note, that the advisory at [1] mentions that affected versions are
> only > 1.45.x. Looking at the git changes, is it not introduced after
> 6dd44caa35b4 ("unix,win: support IDNA 2008 in uv_getaddrinfo()") in
> v1.24.0?

The advisory has been changed and list v1.24.0 as affected version.

I'm going to pacakge v1.48 to fix this issue in unstable.

I'm still pondering what should be done for stable which ships a libuv 1.44.2

All the best

[toc] | [prev] | [next] | [standalone]


#356617

FromDominique Dumont <dod@debian.org>
Date2024-02-20 19:20 +0100
Message-ID<I9CSJ-btdl-1@gated-at.bofh.it>
In reply to#356357

[Multipart message — attachments visible in raw view] — view raw

Hi

On Wed, 14 Feb 2024 12:57:52 +0100 Dominique Dumont <dod@debian.org> wrote:
> I'm still pondering what should be done for stable which ships a libuv 
1.44.2

I've prepared a fix for bookworm. You'll find the debdiff in attachment.

Please tell me if I can upload this package to bookworm-security.

All the best

[toc] | [prev] | [next] | [standalone]


#357480

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-02-29 22:00 +0100
Message-ID<IcVFx-dx4p-9@gated-at.bofh.it>
In reply to#356617
Hi Dominique,

[Adding CC to team@s.d.o]

On Tue, Feb 20, 2024 at 07:08:48PM +0100, Dominique Dumont wrote:
> Hi
> 
> On Wed, 14 Feb 2024 12:57:52 +0100 Dominique Dumont <dod@debian.org> wrote:
> > I'm still pondering what should be done for stable which ships a libuv 
> 1.44.2
> 
> I've prepared a fix for bookworm. You'll find the debdiff in attachment.
> 
> Please tell me if I can upload this package to bookworm-security.

Thanks for preparing the update, I will try to have a look at the
debdiff in the next days.

libuv1 is as well affected in bullseye and it's still supported. Can
you have a look as well at this version? 

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#356557 — Bug#1063484: marked as done (libuv1: CVE-2024-24806)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-02-19 09:00 +0100
SubjectBug#1063484: marked as done (libuv1: CVE-2024-24806)
Message-ID<I96Jc-b9zF-3@gated-at.bofh.it>
In reply to#356054

[Multipart message — attachments visible in raw view] — view raw

Your message dated Mon, 19 Feb 2024 07:49:25 +0000
with message-id <E1rbyOz-00BoUC-C6@fasolo.debian.org>
and subject line Bug#1063484: fixed in libuv1 1.48.0-1
has caused the Debian Bug report #1063484,
regarding libuv1: CVE-2024-24806
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1063484: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063484
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#358044

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-03-06 21:10 +0100
Message-ID<If5Kp-eSaR-1@gated-at.bofh.it>
In reply to#356054
Hi

On Wed, Mar 06, 2024 at 07:06:55PM +0100, Dominique Dumont wrote:
> On Tuesday, 5 March 2024 22:15:50 CET Salvatore Bonaccorso wrote:
> > The debdiff for bookworm-security looks good to me. Please do upload
> > to security-master (and make sure to build with -sa as the orig
> > tarball is not yet on security-master for 1.44.2).
> 
> Done.

Thank you, builds arrived.

> > So we just need as well the bullseye-security one, as per above, can
> > you prepare this one as well.
> 
> Done. Here's the debdiff in attachment

Thank you very much. Looks good to me, feel free to upload as well to
security-master (and build as well with -sa).

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#358247

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-03-10 15:00 +0100
Message-ID<IgrSy-fHGe-3@gated-at.bofh.it>
In reply to#356054
Hi Dominique,

On Thu, Mar 07, 2024 at 08:58:11AM +0100, Dominique Dumont wrote:
> On Wednesday, 6 March 2024 21:07:56 CET Salvatore Bonaccorso wrote:
> > Thank you very much. Looks good to me, feel free to upload as well to
> > security-master (and build as well with -sa).
> 
> Done.

DSA 5638-1 has been released today. Thanks a lot for your
contribution!

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#359226 — Bug#1063484: marked as done (libuv1: CVE-2024-24806)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-03-17 18:10 +0100
SubjectBug#1063484: marked as done (libuv1: CVE-2024-24806)
Message-ID<Ij2bg-hlVR-27@gated-at.bofh.it>
In reply to#356054

[Multipart message — attachments visible in raw view] — view raw

Your message dated Sun, 17 Mar 2024 17:02:40 +0000
with message-id <E1rltuC-00AgdI-Il@fasolo.debian.org>
and subject line Bug#1063484: fixed in libuv1 1.44.2-1+deb12u1
has caused the Debian Bug report #1063484,
regarding libuv1: CVE-2024-24806
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1063484: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063484
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#359361 — Bug#1063484: marked as done (libuv1: CVE-2024-24806)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-03-18 23:10 +0100
SubjectBug#1063484: marked as done (libuv1: CVE-2024-24806)
Message-ID<Ijtl8-1l3-13@gated-at.bofh.it>
In reply to#356054

[Multipart message — attachments visible in raw view] — view raw

Your message dated Mon, 18 Mar 2024 22:02:34 +0000
with message-id <E1rmL3y-00Gr9e-Fe@fasolo.debian.org>
and subject line Bug#1063484: fixed in libuv1 1.40.0-2+deb11u1
has caused the Debian Bug report #1063484,
regarding libuv1: CVE-2024-24806
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1063484: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063484
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.rc


csiph-web