Bug 913071 (CVE-2014-8154) - VUL-0: CVE-2014-8154: vala: Heap-buffer overflow in vala-gstreamer bindings at Gst.MapInfo()
Summary: VUL-0: CVE-2014-8154: vala: Heap-buffer overflow in vala-gstreamer bindings a...
Status: RESOLVED FIXED
Alias: CVE-2014-8154
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/112224/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-14 10:59 UTC by Victor Pereira
Modified: 2015-02-19 02:04 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-01-14 10:59:55 UTC
CVE-2014-8154

Sergey "Shnatsel" Davidoff  reported a heap-based buffer overflow in Vala Gstreamer bindings in the Gst.MapInfo() function. Further details are available in the following Red Hat bug: https://bugzilla.redhat.com/show_bug.cgi?id=1177840

References:

https://git.gnome.org/browse/vala/commit/?id=3092537db65887e24a3d3e87a27caf9c5295e4f7 (fix)
https://bugzilla.redhat.com/show_bug.cgi?id=1181404
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8154
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8154
Comment 1 Frederic Crozat 2015-01-14 11:52:25 UTC
Please note (from the RH bug report): 
"All binaried built with the buggy bindings package that use Gst.MapInfo() function are affected. Binaries such as shotwell-video-thumbnailer run this function on untrusted input, which probably makes this bug fairly easy to exploit."

This implies shotwell, but I don't know how many others are affected :(
Comment 2 Dominique Leuenberger 2015-01-14 11:53:42 UTC
Affected openSUSE releases: 13.2 & Tumbleweed

for 13.2: preparing update
for TW  : Updated vala version should hit fairly soon

The 'main issue' will be to identify the packages requiring a rebuild.
Comment 3 Frederic Crozat 2015-01-14 15:24:36 UTC
It looks like shotwell in SLED12 is not affected
Comment 4 Swamp Workflow Management 2015-01-14 23:02:23 UTC
bugbot adjusting priority
Comment 5 Dominique Leuenberger 2015-01-22 16:42:23 UTC
Update submitted - assigning to maintenance for followup
Comment 6 Marcus Meissner 2015-01-22 16:54:15 UTC
while vala is shipped on the SLE12 BSK, we probably do not need to update it there.

opensuse update will be released soonish
Comment 7 Swamp Workflow Management 2015-01-23 19:06:36 UTC
openSUSE-SU-2015:0131-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 913071
CVE References: CVE-2014-8154
Sources used:
openSUSE 13.2 (src):    shotwell-0.20.1-5.2, vala-0.26.1-4.1