Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 117481
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
xpdf300_combined.diff xpdf300_combined.diff patch Thierry Carrez (RETIRED) 2006-01-03 05:17 0000 8.50 KB Details | Diff
xpdf202_combined.diff xpdf202_combined.diff patch Thierry Carrez (RETIRED) 2006-01-03 05:17 0000 6.89 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 117481 depends on: Show dependency tree
Bug 117481 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-01-02 13:05 0000
Opening separate bugs for cups, poppler, gpdf. 

Handling pdftohtml, tetex, pdff, kword on their respective bugs that are still
open.

kpdf and kword already silently patched in CVS.

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-01-02 13:08:31 0000 -------
CC'ing metalgod for advise. If you commit please only mention the bug # in the
Changelog for now.

------- Comment #2 From Sune Kloppenborg Jeppesen 2006-01-02 14:50:50 0000 -------
metalgod is short on time, CC'ing dang as well.

------- Comment #3 From Daniel Gryniewicz 2006-01-02 16:51:15 0000 -------
Are there any fixed patches for this?  None of us are actually devs for
xpdf/poppler/etc...

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-01-03 00:17:48 0000 -------
The patch useb by kpdf and kword is in Portage. I hope there will be an
official upstream patch soon.

------- Comment #5 From Thierry Carrez (RETIRED) 2006-01-03 05:17:08 0000 -------
Created an attachment (id=76071) [details]
xpdf300_combined.diff

Combined xpdf-3 patch from Ludwig Nussel. Might include some already-fixed
issues so might need some cleanup.

------- Comment #6 From Thierry Carrez (RETIRED) 2006-01-03 05:17:44 0000 -------
Created an attachment (id=76072) [details]
xpdf202_combined.diff

Combined xpdf-2 patch from Ludwig Nussel, in case it's needed by some tools.

------- Comment #7 From Sune Kloppenborg Jeppesen 2006-01-03 07:42:20 0000 -------
Printing please provide an updated ebuild.

------- Comment #8 From Stefan Schweizer 2006-01-03 15:03:32 0000 -------
The diff returns a lot of failed hunks when i try to apply it on poppler, do we
have a native poppler patch somewhere?

------- Comment #9 From Daniel Gryniewicz 2006-01-05 10:16:44 0000 -------
poppler is bumped to poppler-0.4.3-r4 with this fix.  Xpdf is not yet done.

------- Comment #10 From Daniel Gryniewicz 2006-01-05 12:03:24 0000 -------
xpdf-3.01-r5 is bumped with these fixes.

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-01-05 13:32:05 0000 -------
Arches please test and mark stable.

------- Comment #12 From Markus Rothe 2006-01-05 14:25:50 0000 -------
stable on ppc64

------- Comment #13 From Sune Kloppenborg Jeppesen 2006-01-05 22:22:14 0000 -------
Handling stable marking of Xpdf on bug #117495, please see that bug for details
about stable marking.

------- Comment #14 From Jeroen Roovers 2006-01-09 08:31:34 0000 -------
app-text/xpdf-3.01-r5 marked stable on hppa.

------- Comment #15 From Gustavo Zacarias (RETIRED) 2006-01-11 05:54:27 0000 -------
sparc done, i think :)

------- Comment #16 From Tobias Scherbaum 2006-01-11 07:58:14 0000 -------
ppc stable

------- Comment #17 From Simon Stelling (RETIRED) 2006-01-12 08:14:02 0000 -------
amd64 stablized as mentioned in bug 117495

------- Comment #18 From Robin Johnson 2006-01-12 14:47:09 0000 -------
as the maintainer for pdftohtml, could I please be CC when these holes crop up?
I'm not a member of the printing herd.

Related to Xpdf security holes, I was just reviewing pdftohtml's existing
patches vs. poppler, and I noticed that poppler seems to be missing the fixes
from xpdf2-underflow.patch. Could the security team or the poppler maintainers
please take a look at it?

Seeing how poppler and pdftohtml are diverging, I'd like to know of any
functionality differences in the pdftohtml provided by the pdftohtml from each
of the poppler and pdftohtml codebases. The only one I see at a glance is the
-nodrm stuff in poppler. (FYI even the poppler pdftohtml claims to be
pdftohtml-0.36, might want to change that ;-).

------- Comment #19 From Mark Loeser 2006-01-12 17:48:56 0000 -------
x86 done

------- Comment #20 From Sune Kloppenborg Jeppesen 2006-01-12 22:31:34 0000 -------
Robbat, see bug #115789 for the pdftohtml bug.

Printing please advise on missing patch.

------- Comment #21 From Robin Johnson 2006-01-12 23:35:24 0000 -------
jaervosz: Yes I see #115789. We're trying to figure if pdftohtml should just be
dropped in favour of poppler, as they do seem to be reasonably close in terms
of functionality.

------- Comment #22 From Sune Kloppenborg Jeppesen 2006-01-13 15:16:28 0000 -------
And stable marking can continue:-)

[00:15:06] <@taviso> jaervosz: looks like poppler doesnt need the underflow
patch
[00:15:12] <@taviso> so i would say, safe

------- Comment #23 From Sune Kloppenborg Jeppesen 2006-01-16 14:16:21 0000 -------
Bahh sorry for the bug spam. Stable marking is on bug #117495

------- Comment #24 From Robin Johnson 2006-01-25 23:14:01 0000 -------
pdftohtml is now in p.mask, and will be removed early next week (keeping it
around for a few days in case problems crop up).

I've changed all deps in the tree (sys-cluster/charm and
app-zope/portaltransforms for those keeping track) to point to poppler instead.

The dep blocker in poppler of "!app-text/poppler" remains, as a way to force
users to uninstall pdftohtml and move to poppler instead.

------- Comment #25 From Sune Kloppenborg Jeppesen 2006-01-26 05:16:02 0000 -------
We should probably push this info to the GWN team.

------- Comment #26 From Sune Kloppenborg Jeppesen 2006-01-27 23:09:12 0000 -------
Mail send to GWN a few days ago.

------- Comment #27 From Sune Kloppenborg Jeppesen 2006-01-30 14:39:52 0000 -------
GLSA 200601-17

------- Comment #28 From Sune Kloppenborg Jeppesen 2006-01-31 02:37:39 0000 -------
And now actually closing.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug