First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 139823
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Pacho Ramos <pacho@condmat1.ciencias.uniovi.es>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 139823 depends on: 144120 Show dependency tree
Show dependency graph
Bug 139823 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-09 15:21 0000
Abiword 2.4.5 has been released:
http://www.abisource.com/release-notes/2.4.5.phtml
http://www.abisource.com/changelogs/2.4.5.phtml

Thanks for updating the ebuild :-)

------- Comment #1 From Gustavo Zacarias (RETIRED) 2006-07-10 09:58:02 0000 -------
Revbumped, thanks for the news.
Security: The ChangeLog mentions a security bug fix "Fix a security bug that
was reported to us by Joxean Koret (thanks a lot!). A stack corruption could be
triggered in the toolbar code by loading a document which contained a style
with an insanely long name (afftects only Windows and Unix)".
It is unclear if this affects the 2.2.x branch (current stable). Please advise.

------- Comment #2 From Thierry Carrez (RETIRED) 2006-08-02 07:03:44 0000 -------
Reassigning to security for a decision

------- Comment #3 From Sune Kloppenborg Jeppesen 2006-08-02 08:21:47 0000 -------
Taviso or someone else, please check wether this affects 2.2.x

------- Comment #4 From Christian Faulhammer 2006-08-16 23:55:47 0000 -------
Can we close this bug, because 2.4.5 is getting stabled

------- Comment #5 From Raphael Marichez 2006-08-17 00:50:32 0000 -------
i have really no detail on this potential issue. BTW, a stack overflow merits a
GLSA... anybody knows if 2.2.x was affected or has a link to the patch ?

Additionnally, i suggest to remove from the tree the 2.4.x vulnerable versions
(x<5).

------- Comment #6 From Raphael Marichez 2006-08-28 02:48:16 0000 -------
heya sec team, holidays have finished, please vote :)

------- Comment #7 From Sune Kloppenborg Jeppesen 2006-08-29 11:18:10 0000 -------
I can't find any details about this issue. So given that impact is unknown I
vote NO.

------- Comment #8 From Raphael Marichez 2006-09-05 11:22:34 0000 -------
OK, so no glsa on this.

Is 2.2.x affected ? AMD64 is still with 2.2.11 as the latest stable version.

------- Comment #9 From Raphael Marichez 2006-09-07 07:05:56 0000 -------
amd64 is done now. Closing with noglsa, feel free to reopen if blabla

------- Comment #10 From Raphael Marichez 2006-09-07 07:06:04 0000 -------
amd64 is done now. Closing with noglsa, feel free to reopen if blabla

First Last Prev Next    No search results available      Search page      Enter new bug