Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 100263
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
xpdf-3.00-ttf-cid-fix.dif xpdf-3.00-ttf-cid-fix.dif patch Sune Kloppenborg Jeppesen 2005-07-27 06:43 0000 12.18 KB Details | Diff
post-3.3.1-kdegraphics-4.diff post-3.3.1-kdegraphics-4.diff patch Sune Kloppenborg Jeppesen 2005-07-27 06:45 0000 1.75 KB Details | Diff
post-3.4.1-kdegraphics-4.diff post-3.4.1-kdegraphics-4.diff patch Sune Kloppenborg Jeppesen 2005-07-27 06:46 0000 1.78 KB Details | Diff
kdegraphics-3.4.1-r1.ebuild kdegraphics-3.4.1-r1.ebuild text/plain Carsten Lohrke 2005-08-02 17:06 0000 1.41 KB Details
kdegraphics-3.3.2-r3.ebuild kdegraphics-3.3.2-r3.ebuild text/plain Carsten Lohrke 2005-08-02 17:07 0000 1.58 KB Details
kpdf-3.4.1-r1.ebuild kpdf-3.4.1-r1.ebuild text/plain Carsten Lohrke 2005-08-02 17:07 0000 530 bytes Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 100263 depends on: Show dependency tree
Bug 100263 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-07-25 11:52 0000
See bug #99769.

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-07-27 06:42:13 0000 -------
This is fixed in 3.4.2. 

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-07-27 06:43:20 0000 -------
Created an attachment (id=64438) [details]
xpdf-3.00-ttf-cid-fix.dif

This one needs to be applied before the patch on the parent bug applies.

------- Comment #3 From Sune Kloppenborg Jeppesen 2005-07-27 06:45:48 0000 -------
Created an attachment (id=64439) [details]
post-3.3.1-kdegraphics-4.diff

Official upstream patch for 3.3.1.

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-07-27 06:46:28 0000 -------
Created an attachment (id=64440) [details]
post-3.4.1-kdegraphics-4.diff

Official upstream patch for 3.4.1.

------- Comment #5 From Carsten Lohrke 2005-08-02 17:06:53 0000 -------
Created an attachment (id=64960) [details]
kdegraphics-3.4.1-r1.ebuild

------- Comment #6 From Carsten Lohrke 2005-08-02 17:07:22 0000 -------
Created an attachment (id=64961) [details]
kdegraphics-3.3.2-r3.ebuild

------- Comment #7 From Carsten Lohrke 2005-08-02 17:07:49 0000 -------
Created an attachment (id=64962) [details]
kpdf-3.4.1-r1.ebuild

------- Comment #8 From Carsten Lohrke 2005-08-02 17:09:50 0000 -------
KOffice is not affected this time. Any news about the common xpdf,gpdf,kde.org
announcement date?

------- Comment #9 From Sune Kloppenborg Jeppesen 2005-08-02 22:17:17 0000 -------
Arches please test and mark stable/report back on this bug.  
  
Carlo no news from upstream yet and you're free to commit, patches are already 
public, though no advisories yet. 

------- Comment #10 From Thierry Carrez (RETIRED) 2005-08-03 00:48:35 0000 -------
carlo: you can doublecheck the issue is fixed using a testcase PDF you will
find
on toucan at ~koon/foo.pdf. This one should grow a file in /tmp until
filesystem
is full. Kill your process in time :)

For gpdf they had to adapt the patch a little and when tested using the
testcase
it revealed that the patched version wasn't working better :/ So better make
sure the patch indeed works.

NB: apparently when allanonJL tested the problem in gpdf, it was triggered by
going to the second page (just opening the first page didn't trigger the
problem).

------- Comment #11 From Gustavo Zacarias (RETIRED) 2005-08-03 06:20:41 0000 -------
CCing weeve on this one - he's better suited for kde on sparc.

------- Comment #12 From René Nussbaumer 2005-08-03 08:53:30 0000 -------
Add gmsoft for testing. He has already kde installed.

------- Comment #13 From Olivier Crete 2005-08-03 09:02:36 0000 -------
can carlo or other kde ppl do x86? I dont have kde.

------- Comment #14 From Carsten Lohrke 2005-08-03 10:12:51 0000 -------
(In reply to comment #10)
> carlo: you can doublecheck the issue is fixed using a testcase PDF you will find

Did it, all fine.


(In reply to comment #9)
> Carlo no news from upstream yet and you're free to commit, patches are already 
> public, though no advisories yet. 

You'll drive me crazy with this un-/disclosed vendor-sec sh.t. ;) On the kde
packager list Dirk Mueller used the word undisclosed for this issue at least.


(In reply to comment #13)
> can carlo or other kde ppl do x86? I dont have kde.

I'd have committed the ebuilds directly, if I had known that it is o.k. this time.

<<< kpdf-3.4.1-r1.ebuild
<<< kdegraphics-3.3.2-r3.ebuild
<<< kdegraphics-3.4.1-r1.ebuild

------- Comment #15 From Diego E. 'Flameeyes' Pettenò 2005-08-03 10:18:13 0000 -------
Here (~amd64) I'm both able to reproduce the bug with 3.4.1, and to fix it 
with the given patch. It also works fine with 3.4.2. 

------- Comment #16 From Sune Kloppenborg Jeppesen 2005-08-03 11:41:11 0000 -------
This is how we handle this type of bug: 
 
The third (and less secret) type of restricted bugs is the SEMI-PUBLIC bugs. 
Semi-public bugs should be kept secret, but patches may be committed to 
portage. This is generally when the vulnerability is not known to the general 
public but could be accessed by anyone (patch in upstream CVS for example). 

------- Comment #17 From Jason Wever (RETIRED) 2005-08-03 20:32:37 0000 -------
Can someone add me to bug #99769 so I can see what the problem is so I can test
to make sure the fix is working on SPARC?

------- Comment #18 From Guy Martin 2005-08-04 10:19:19 0000 -------
Works fine on hppa. No more big file in /tmp and the second page is displayed
correctly.

------- Comment #19 From Jason Wever (RETIRED) 2005-08-06 18:38:48 0000 -------
Looking good on SPARC, stablized kdegraphics.

------- Comment #20 From Sune Kloppenborg Jeppesen 2005-08-06 23:47:01 0000 -------
This will be public on Tuesday. We still need the following keywords (unless   
some arches are dropping support for 3.3.2):    
    
kdegraphics-3.3.2-r3: alpha amd64 hppa ia64 mips ppc ppc64   
kdegraphics-3.4.1-r1: amd64 ppc hppa  
kpdf-3.4.1-r1: amd64 ppc ppc64 sparc 
  

------- Comment #21 From Bryan Østergaard (RETIRED) 2005-08-07 07:19:34 0000 -------
Alpha + ia64 stabilized.

------- Comment #22 From Markus Rothe 2005-08-07 10:10:08 0000 -------
marked kpdf-3.4.1-r1 and kdegraphics-3.3.2-r3 stable on ppc64.

------- Comment #23 From Diego E. 'Flameeyes' Pettenò 2005-08-07 10:23:49 0000 -------
Stable on amd64. 

------- Comment #24 From Jason Wever (RETIRED) 2005-08-07 16:27:19 0000 -------
kpdf-3.4.1-r1 now stable on SPARC.

------- Comment #25 From Sune Kloppenborg Jeppesen 2005-08-08 10:38:16 0000 -------
CC'ing ppc guys, please test and mark stable asap and sorry for the short 
notice. 

------- Comment #26 From Jory A. Pratt 2005-08-08 10:52:23 0000 -------
Stable on ppc.

------- Comment #27 From Sune Kloppenborg Jeppesen 2005-08-08 11:58:50 0000 -------
Only needing hppa (and mips once this go public). 

------- Comment #28 From Guy Martin 2005-08-08 13:14:44 0000 -------
both version of kdegraphics stable on hppa. sorry for the delay

------- Comment #29 From Thierry Carrez (RETIRED) 2005-08-09 00:39:57 0000 -------
client-based DoS -> downgrading severity

------- Comment #30 From Sune Kloppenborg Jeppesen 2005-08-09 13:24:33 0000 -------
mips please mark stable. 
 
This is now public and ready for GLSA decision. I tend to vote NO. 

------- Comment #31 From Thierry Carrez (RETIRED) 2005-08-09 13:36:40 0000 -------
I tend to vote NO too. DoS by social-engineer someone to open a file in KPDF ?
Highly unlikely.

------- Comment #32 From Thierry Carrez (RETIRED) 2005-08-12 02:49:48 0000 -------
Or maybe we can make one once gpdf is also fixed ?

------- Comment #33 From Sune Kloppenborg Jeppesen 2005-08-12 04:08:41 0000 -------
Waiting for common xpdf GLSA. 

------- Comment #34 From Sune Kloppenborg Jeppesen 2005-08-15 22:27:06 0000 -------
GLSA ID:  200508-08 

------- Comment #35 From Hardave Riar (RETIRED) 2005-09-29 09:23:43 0000 -------
kdegraphics-3.3.2-r3 stable on mips.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug