Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1130755

Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption

From "Steinar H. Gunderson" <sesse@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption
Date 2022-12-30 12:00 +0100
Message-ID <FIlhf-ejel-3@gated-at.bofh.it> (permalink)
References (2 earlier) <F1ElA-54dV-7@gated-at.bofh.it> <EYMSm-3gp8-1@gated-at.bofh.it> <FIkuT-eiXY-3@gated-at.bofh.it> <EYMSm-3gp8-1@gated-at.bofh.it> <FIkuT-eiXY-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, Dec 30, 2022 at 11:04:46AM +0100, Tobias Frost wrote:
> I was trying to triage this CVE and *maybe* those revisions are related:
> 
> r1894937 ("apreq_parse_headers: Discard CRLF of folded values.")
> r1894940 ("reindent (no functional change).") 
> r1894977 ("Follow up to r1894937: Fix setting of empty value.")
> r1895054 ("Follow up to r1894937: Always eat CRLF at the end of header value.")

Perhaps it's best to remove libapreq2 entirely? I don't use nor maintain it
anymore, it's been out of testing for a while, and there's this CVE.

/* Steinar */
-- 
Homepage: https://www.sesse.net/

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption "Steinar H. Gunderson" <sesse@debian.org> - 2022-12-30 12:00 +0100
  Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Tobias Frost <tobi@debian.org> - 2022-12-30 12:10 +0100
    Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Tobias Frost <tobi@debian.org> - 2022-12-30 12:40 +0100
    Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption "Steinar H. Gunderson" <sesse@debian.org> - 2022-12-30 12:40 +0100
    Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Salvatore Bonaccorso <carnil@debian.org> - 2022-12-30 19:10 +0100

csiph-web