Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 100274
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 100274 depends on: Show dependency tree
Bug 100274 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-07-25 12:31 0000
In util.c

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-07-25 12:33:45 0000 -------
Ferdy please provide an updated ebuild. 

------- Comment #2 From Fernando J. Pereda (RETIRED) 2005-07-28 18:15:58 0000 -------
nbsmtp-1.00 (which fixes the problem) added with keywords:

alpha ~amd64 ~hppa ~ppc ~sparc x86

Cheers,
Ferdy

------- Comment #3 From Sune Kloppenborg Jeppesen 2005-07-28 22:49:15 0000 -------
Arches please test and mark stable. 

------- Comment #4 From Tobias Scherbaum 2005-07-29 05:28:33 0000 -------
ppc stable

------- Comment #5 From Gustavo Zacarias (RETIRED) 2005-07-29 07:24:57 0000 -------
sparc stable.

------- Comment #6 From Thierry Carrez (RETIRED) 2005-07-30 01:37:18 0000 -------
On further investigation, I am not sure this is a vulnerability at all. This is
an SMTP client, not a daemon, so the attack is local and may be used to elevate
privileges to... yourself ?

------- Comment #7 From Fernando J. Pereda (RETIRED) 2005-07-30 02:34:08 0000 -------
mmmm nope. A malicious server 'might' inject code; I had a:

syslog(something,string_from_server);

where I should have:

syslog(something,"%s",string_from_server);

HTH

Cheers,
Ferdy

------- Comment #8 From Thierry Carrez (RETIRED) 2005-07-30 03:37:02 0000 -------
Thanks for the details. Rerating B2. I'll ask for a CAN number to MITRE.

------- Comment #9 From Thierry Carrez (RETIRED) 2005-07-30 06:35:11 0000 -------
This is still missing the hppa keyword.

------- Comment #10 From René Nussbaumer 2005-07-30 13:56:31 0000 -------
Stable on hppa

------- Comment #11 From Thierry Carrez (RETIRED) 2005-07-31 04:25:27 0000 -------
Ready for GLSA, waiting a little for the CAN number to be attributed.

------- Comment #12 From Thierry Carrez (RETIRED) 2005-08-02 05:46:23 0000 -------
Enough waiting, we'll add the CAN afterwards when it is attributed.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-08-02 06:03:19 0000 -------
GLSA 200508-03

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug