First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 111853
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 111853 depends on: Show dependency tree
Show dependency graph
Bug 111853 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-11-08 02:12 0000
Colin Leroy has found three buffer overflows in Sylpheed and Sylpheed-Claws.
They are locally exploitable and could allow execution of code as the
current user.

One of them is in the LDIF importer, accessible from the Addressbook
(Tools menu). If the chosen file has a line longer than 2047 chars,
sylpheed(-claws) will segfault because the program will try to write
after the end of a 2048 chars static buffer. I don't know if this can
be exploited.

The other two are similar and concern only Sylpheed-Claws. They happen
in the Mutt and Pine addressbook importers found in the same place, and
the problem is the same.

Vulnerable versions:
Sylpheed: from 0.6.4 to 2.0.3 (stable), 2.1.5 (development), 1.0.5 (old)
Sylpheed-Claws: from 0.6.4 to 1.9.99 (included)

Fixed versions:
Sylpheed: >= 2.0.4 (stable), 2.1.6 (development), 1.0.6 (old)
Sylpheed-Claws: >= 1.9.100

------- Comment #1 From Thierry Carrez (RETIRED) 2005-11-08 02:19:15 0000 -------
This is semi-public, meaning it's not been announced yet but can be found in
upstream CVS. We are free to commit new releases to Portage.

hattya: we should add the following fixed versions :
sylpheed-2.0.4 (stable)
sylpheed-2.1.6 (~/masked)

genone: for sylpheed-claws, we might need to backport the fix for our 1.0.5
stable line, as only 1.9.100 is released to fix. These are the patches for
sylpheed-claws :

http://colino.net/sylpheed-claws-gtk2/getpatchset.php3?ver=1.9.99cvs13
http://colino.net/sylpheed-claws-gtk2/getpatchset.php3?ver=1.9.99cvs15

------- Comment #2 From Thierry Carrez (RETIRED) 2005-11-10 08:45:01 0000 -------
*** Bug 111872 has been marked as a duplicate of this bug. ***

------- Comment #3 From Thierry Carrez (RETIRED) 2005-11-10 08:45:37 0000 -------
Now completely public, please patch.

------- Comment #4 From Marius Mauch 2005-11-10 10:19:45 0000 -------
will do what I can at the weekend (I'm currently pretty busy during the week),
hopefully the patch for 1.0.5 shouldn't be tricky. The 1.9 branch might take a
bit longer as it also requires updated plugins (this is why .99 is still p.masked).

------- Comment #5 From Marius Mauch 2005-11-11 05:54:29 0000 -------
Ok, committed a 1.0.5-r1 as ~arch and a p.masked 1.9.100 (due to broken
plugins).

------- Comment #6 From Jakub Moc 2005-11-11 11:12:49 0000 -------
*** Bug 112198 has been marked as a duplicate of this bug. ***

------- Comment #7 From Akinori Hattori 2005-11-13 02:05:39 0000 -------
Sylpheed 2.0.4 and 2.1.6 are in CVS.

------- Comment #8 From Marius Mauch 2005-11-13 03:57:47 0000 -------
Sylpheed-claws-1.9.100 unmasked as of a few minutes ago. All that remains to do
for -claws is marking 1.0.5-r1 stable.

------- Comment #9 From Matthias Geerdsen 2005-11-13 03:59:14 0000 -------
arches, please test and mark stable if possible:

mail-client/sylpheed-2.0.4:
target keywords: "alpha amd64 hppa ia64 ppc ~ppc64 sparc x86"

mail-client/sylpheed-claws-1.0.5-r1:
target keywords: "alpha amd64 ppc ppc64 sparc x86"

------- Comment #10 From Brent Baude 2005-11-13 05:04:19 0000 -------
marked both ppc64 stable.

------- Comment #11 From Michael Hanselmann (hansmi) (RETIRED) 2005-11-13 10:26:26 0000 -------
ppc and hppa done.

------- Comment #12 From Jason Wever (RETIRED) 2005-11-13 10:57:33 0000 -------
SPARCy SPARC and the stable bunch

------- Comment #13 From Jose Luis Rivero (yoswink) 2005-11-14 02:35:42 0000 -------
marked both stable on alpha.

------- Comment #14 From Chris Gianelloni (RETIRED) 2005-11-14 06:54:50 0000 -------
x86 is feeling a bit of those good vibrations, too...

------- Comment #15 From Simon Stelling (RETIRED) 2005-11-14 13:18:47 0000 -------
sylpheed doesn't like it when you don't give true settings, it hangs when you
try to set up an account for dev.g.o on port 143... it hangs and you have to
kill it. however, 2.0.1 has the same behaviour, so this gets the amd64 keyword
nevertheless.
both marked stable on amd64

------- Comment #16 From Thierry Carrez (RETIRED) 2005-11-15 06:15:25 0000 -------
Thx everyone...

GLSA 200511-13
ia64 should mark stable to benefit from GLSA

First Last Prev Next    No search results available      Search page      Enter new bug