First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 114583
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 114583 depends on: Show dependency tree
Bug 114583 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-12-05 17:19 0000
--- ./kxsldbg/kxsldbgpart/libxsldbg/file_cmds.cpp.orig  2005-12-04
11:02:02.000000000 +0100
+++ ./kxsldbg/kxsldbgpart/libxsldbg/file_cmds.cpp       2005-12-04
11:04:00.000000000 +0100
@@ -175,7 +175,7 @@
         } else {
            xsldbgGenericErrorFunc(i18n("PublicID \"%1\" was not found in
current catalog.\n").arg(xsldbgText(arg)));
         }
-        xsltGenericError(xsltGenericErrorContext, buffer);
+        xsltGenericError(xsltGenericErrorContext, "%s", buffer);
     }
     return result;
 }

------- Comment #1 From Carsten Lohrke 2005-12-05 17:30:59 0000 -------
Here we go...

<<< kxsldbg-3.4.3-r1.ebuild
<<< kdewebdev-3.4.3-r1.ebuild


------- Comment #2 From Michael Hanselmann (hansmi) (RETIRED) 2005-12-06 13:50:50 0000 -------
ppc and hppa done.

------- Comment #3 From Gustavo Zacarias (RETIRED) 2005-12-07 05:25:31 0000 -------
sparc stable.

------- Comment #4 From Marcus D. Hanwell 2005-12-07 11:55:15 0000 -------
Stable on amd64. 

------- Comment #5 From Mark Loeser 2005-12-07 14:09:34 0000 -------
x86 needs this backported to 3.4.1 as we don't have 3.4.3 stable yet.  cpw is
still trying to work out the remaining issues before we mark KDE-3.4.3 stable.

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-12-07 22:44:22 0000 -------
Carlo we need it backported as per above comment. 

------- Comment #7 From Carsten Lohrke 2005-12-08 05:10:12 0000 -------
(In reply to comment #6)
> Carlo we need it backported as per above comment. 

It is. I thought a comment in one bug suffices.

------- Comment #8 From Sune Kloppenborg Jeppesen 2005-12-08 06:13:22 0000 -------
Thx Carlo. Unless otherwise noted one comment applies to one bug for me:-) 
 
Back to stable marking. 

------- Comment #9 From Mark Loeser 2005-12-10 00:01:57 0000 -------
x86 done

------- Comment #10 From Jose Luis Rivero (yoswink) 2005-12-10 09:58:39 0000 -------
kxsldbg-3.4.1-r1 and kdewebdev-3.4.1-r1 are stable on alpha.

Thanks to carlo for backporting the patches. This make our life much easier.

------- Comment #11 From Thierry Carrez (RETIRED) 2005-12-12 03:40:29 0000 -------
shouldn't ppc64 also mark stable ?

------- Comment #12 From Markus Rothe 2005-12-12 11:18:16 0000 -------
kxsldbg-3.4.1-r1 stable on ppc64. kdewebdev-3.4.x not even ~ppc64. 

------- Comment #13 From Thierry Carrez (RETIRED) 2005-12-13 10:27:46 0000 -------
ppc64 has kxsldbg-3.4.3 stable so might need to mark 3.4.3-r1 too ?

------- Comment #14 From Markus Rothe 2005-12-13 13:11:16 0000 -------
yes, you are right. my misstake. kxsldbg-3.4.3-r1 is stable on ppc64 now. 

------- Comment #15 From Sune Kloppenborg Jeppesen 2005-12-14 04:24:33 0000 -------
Should we do a GLSA on this one? I see no other advisories, not even from KDE. 

------- Comment #16 From Thierry Carrez (RETIRED) 2005-12-14 05:00:14 0000 -------
The exploit path is a little weird. Probably takes a malicious XSL file to be
imported ? I tend to vote yes nevertheless, but I would welcome input from the
reporter (Carsten ?).

------- Comment #17 From Thierry Carrez (RETIRED) 2005-12-14 05:17:47 0000 -------
Based on draft comment, I revert to 1/2 NO

------- Comment #18 From Carsten Lohrke 2005-12-14 09:00:12 0000 -------
(In reply to comment #16)
> The exploit path is a little weird. Probably takes a malicious XSL file to be
> imported ?

Yes. I pushed it to you, since this is the Gentoo way for this sort of bugs, but
it's highly unlikely that you grab such a xsl file and process it with kxsldbg.
In KDE svn the KDE 3.4 branch wasn't even fixed, I'm pretty sure there won't be
an announcment and don't think we need one either.



------- Comment #19 From Thierry Carrez (RETIRED) 2005-12-14 10:02:41 0000 -------
Heh, full NO from me then. Another NO voter can close this one as FIXED/noglsa

------- Comment #20 From Sune Kloppenborg Jeppesen 2005-12-14 13:30:06 0000 -------
NO 

First Last Prev Next    No search results available      Search page      Enter new bug