Bug 917129 (CVE-2014-9654) - VUL-0: CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler
Summary: VUL-0: CVE-2014-9654 icu: insufficient size limit checks in regular expressio...
Status: RESOLVED FIXED
Alias: CVE-2014-9654
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2015-02-26
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113591/
Whiteboard: maint:released:sle11-sp3:62029 CVSSv2...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-10 14:54 UTC by Johannes Segitz
Modified: 2015-11-27 15:47 UTC (History)
9 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-02-10 14:54:31 UTC
Regular expression pattern size limits weren't checked.

Change:
http://bugs.icu-project.org/trac/changeset/36801

SLE 12 needs the patch, SLE 11 SP3 is probably also affected.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1190129
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9654
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9654.html
Comment 1 Swamp Workflow Management 2015-02-10 23:00:33 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2015-02-12 10:28:02 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-02-26.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60661
Comment 3 Dirk Mueller 2015-02-12 10:52:41 UTC
I don't maintain SLE12 packages.
Comment 4 Johannes Segitz 2015-02-12 10:58:13 UTC
SLE 11 is affected and you're still listed as the maintainer. Do you know who took this package?
Comment 5 Dirk Mueller 2015-02-12 11:29:09 UTC
Ok, sorry, I also don't maintain SLE11 packages, and no, I have no idea who is maintaining those packages these days.
Comment 6 Johannes Segitz 2015-02-12 13:10:54 UTC
Seems like this is your package.
Comment 17 Marcus Meissner 2015-03-04 16:08:18 UTC
The original maintaining team was bnc-team-gnome ... can the Desktop team do that?
Comment 20 Swamp Workflow Management 2015-03-10 14:10:39 UTC
SUSE-SU-2015:0458-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 917129
CVE References: CVE-2014-9654
Sources used:
SUSE Linux Enterprise Workstation Extension 12 (src):    icu-52.1-7.1
SUSE Linux Enterprise Software Development Kit 12 (src):    icu-52.1-7.1
SUSE Linux Enterprise Server 12 (src):    icu-52.1-7.1
SUSE Linux Enterprise Desktop 12 (src):    icu-52.1-7.1
Comment 22 Felix Zhang 2015-04-02 10:49:54 UTC
I have backported the changeset to SLE11-SP3 at
https://build.suse.de/package/show/home:zhangxiaofei:branches:SUSE:SLE-11-SP3:Update:Test/icu

However I must admit I'm not familiar to icu either. So it would be great if somebody could review or test the patch.
Comment 23 Johannes Segitz 2015-04-10 07:24:19 UTC
(In reply to Felix Zhang from comment #22)
I'm also not familiar but I gave it a try. To my not-ICU-expert eyes your submission looks fine, although it is tempting to insert all the missing calls to fixLiterals(), but it's not like the patch isn't already big enough.

Testing will need to be done by QA, but this one looks promising
Comment 29 Marcus Meissner 2015-06-18 11:20:50 UTC
could we also have a fix for sles10 sp3?

SUSE:SLE-10-SP3:Update:Test                             icu
Comment 30 Felix Zhang 2015-06-19 09:44:49 UTC
(In reply to Marcus Meissner from comment #29)
> could we also have a fix for sles10 sp3?
> 
> SUSE:SLE-10-SP3:Update:Test                             icu

Yes. I have backported it here:

https://build.suse.de/package/show/home:zhangxiaofei:branches:SUSE:SLE-10-SP3:Update:Test/icu
Comment 31 Swamp Workflow Management 2015-06-25 17:05:15 UTC
SUSE-SU-2015:1144-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 917129
CVE References: CVE-2014-9654
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    icu-4.0-7.28.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    icu-4.0-7.28.1
SUSE Linux Enterprise Server 11 SP3 (src):    icu-4.0-7.28.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    icu-4.0-7.28.1
Comment 36 Felix Zhang 2015-07-03 09:44:21 UTC
Closing as fixed as the changes are checked in.
Comment 38 Swamp Workflow Management 2015-10-21 08:10:04 UTC
SUSE-SU-2015:1790-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 917129
CVE References: CVE-2014-9654
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    icu-4.0-7.30.2
SUSE Linux Enterprise Server 11-SP4 (src):    icu-4.0-7.30.2
SUSE Linux Enterprise Desktop 11-SP4 (src):    icu-4.0-7.30.2
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    icu-4.0-7.30.2
Comment 39 Marcus Meissner 2015-10-22 06:21:06 UTC
probably all done now
Comment 40 Marcus Meissner 2015-10-28 10:59:25 UTC
This caused a regression , see bug 952260