Bug 890123 (CVE-2014-3564) - VUL-0: CVE-2014-3564: gpgme 1.5.1 Fixes possible overflow in gpgsm and uiserver engines
Summary: VUL-0: CVE-2014-3564: gpgme 1.5.1 Fixes possible overflow in gpgsm and uiserv...
Status: RESOLVED FIXED
Alias: CVE-2014-3564
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-09-04
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle10-sp3:58691 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-03 21:36 UTC by Andreas Stieger
Modified: 2014-09-01 09:56 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
patch for this issue applies back to at least 1.3.2 (openSUSE 12.3) (1.53 KB, patch)
2014-08-03 22:05 UTC, Andreas Stieger
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2014-08-03 21:36:00 UTC
User-Agent:       Mozilla/5.0 (X11; Linux i686; rv:31.0) Gecko/20100101 Firefox/31.0

From http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gpgme.git;a=blob;f=NEWS;h=0ea405bae60b037b22fe5c63de97fed85f40e976;hb=bfe18a0651177025ff0a6b978a641bdd1472a0b1


Noteworthy changes in version 1.5.1 (2014-07-30) [C24/A13/R0]
-------------------------------------------------------------

 * Fixed possible overflow in gpgsm and uiserver engines.
   [CVE-2014-3564]

 * Added support for GnuPG 2.1's --with-secret option.

 * Interface changes relative to the 1.5.0 release:
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 GPGME_KEYLIST_MODE_WITH_SECRET NEW.



Reproducible: Didn't try
Comment 2 Andreas Stieger 2014-08-03 22:05:00 UTC
Created attachment 600820 [details]
patch for this issue applies back to at least 1.3.2 (openSUSE 12.3)
Comment 3 Andreas Stieger 2014-08-03 22:10:09 UTC
1.5.1 for Base:System / gpgme:
https://build.opensuse.org/request/show/243547

Maintenance request with patch openSUSE 12.3 and 13.1:
https://build.opensuse.org/request/show/243548

Please review.

SLE certainly affected, cc bugowner.
Comment 4 Vítězslav Čížek 2014-08-05 10:07:07 UTC
Thanks Andreas,
All SLE gpgme packages are indeed affected.
Comment 5 Andreas Stieger 2014-08-07 18:34:43 UTC
Announcement: http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000350.html

> * Noteworthy changes in version 1.4.4 (2014-07-30)
>  - Fixed possible overflow in gpgsm and uiserver engines.
>    [CVE-2014-3564]
>  - Fixed possibled segv in gpgme_op_card_edit.
>  - Fixed minor memleaks and possible zombie processes.
>  - Fixed prototype inconsistencies and void pointer arithmetic.

They made a maintenance release for gpgme 1.4.x (openSUSE 13.1), propose straight update there.

https://build.opensuse.org/request/show/243910
Comment 6 Swamp Workflow Management 2014-08-20 07:05:25 UTC
openSUSE-SU-2014:1039-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 890123
CVE References: CVE-2014-3564
Sources used:
openSUSE 13.1 (src):    gpgme-1.4.4-2.4.1
openSUSE 12.3 (src):    gpgme-1.3.2-2.4.1
Comment 8 SMASH SMASH 2014-08-21 18:45:16 UTC
Affected packages:

SLE-10-SP3-TERADATA: gpgme
SLE-11-SP1: gpgme
SLE-11-SP3: gpgme
Comment 9 Swamp Workflow Management 2014-08-21 18:47:38 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-09-04.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/58689
Comment 11 Swamp Workflow Management 2014-08-29 03:04:25 UTC
SUSE-SU-2014:1073-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 890123
CVE References: CVE-2014-3564
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    gpgme-1.1.6-25.32.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    gpgme-1.1.6-25.32.1
SUSE Linux Enterprise Server 11 SP3 (src):    gpgme-1.1.6-25.32.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    gpgme-1.1.6-25.32.1
Comment 12 Marcus Meissner 2014-09-01 09:56:29 UTC
was released