First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 141577
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
gd-patches.tar.bz2 gd-patches.tar.bz2 application/octet-stream Francisco Javier 2006-11-02 13:58 0000 26.91 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 141577 depends on: Show dependency tree
Show dependency graph
Bug 141577 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-24 06:25 0000
See bug #135860 for further details.

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-07-24 06:26:01 0000 -------
Mike please advise and patch as necessary.

------- Comment #2 From Thierry Carrez (RETIRED) 2006-08-12 05:25:14 0000 -------
vapier, please advise/fix. kthanx

------- Comment #3 From Sune Kloppenborg Jeppesen 2006-09-05 06:16:12 0000 -------
Vapier, any news on this one?

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-09-13 23:16:54 0000 -------
Vapier, any news on this one?

------- Comment #5 From Sune Kloppenborg Jeppesen 2006-09-26 09:26:30 0000 -------
Vapier, any news on this one?

------- Comment #6 From Matthias Geerdsen 2006-10-03 08:39:09 0000 -------
<@SpanKY> vorlon078: need to contact upstream as they havent done a release yet

------- Comment #7 From Francisco Javier 2006-11-02 13:58:29 0000 -------
Created an attachment (id=101093) [edit]
gd-patches.tar.bz2

update gd with debian patches:

1001_CAN-2004-0941.patch
1002_CVE-2006-2906.patch
1003_fix_aa_segfault.patch
1004_improve_aa_lines.patch
1005_graphviz_sanitize.patch
1006_western_european_fonts.patch
1007_minimize_linking_deps.patch
1008_segfault_invalid_gif.patch

------- Comment #8 From Matthias Geerdsen 2006-11-06 04:07:35 0000 -------
vapier, could you check/apply the needed patch for this issue?

------- Comment #9 From Sune Kloppenborg Jeppesen 2006-11-16 06:29:36 0000 -------
Vapier, any news on this one?

------- Comment #10 From Sune Kloppenborg Jeppesen 2006-11-24 12:21:20 0000 -------
Vapier, any news on this one?

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-12-11 08:32:25 0000 -------
Vapier, any news on this one?

------- Comment #12 From Jakub Moc 2007-01-17 13:42:32 0000 -------
Just an update here, thanks to koredn from #gentoo-php

This project has been moved and is being developed by Pierre Joye (a PHP dev).

<Pierre> kore_: it is already fixed, in gd cvs and php-src (in a cleaner way
btw)" 
<kore_> Pierre, Is there already a ETA for a 2.0.34 release?                    
< koredn> <Pierre> kore_: RC should go out shortly (waiting some autoconf
commit)

http://cvs.php.net/viewcvs.cgi/gd/libgd/

According to Pierre, Gentoo developers already know about this... :P Anyway,
unless vapier feels like doing something here, I'll try to ask CHTEKK to take
over this and stick the package under PHP herd.

------- Comment #13 From SpanKY 2007-01-17 16:48:07 0000 -------
yes, "Gentoo developers" already know this because i've been talking to Pierre
on the GD development lists ... fancy that

------- Comment #14 From Jakub Moc 2007-01-17 17:25:22 0000 -------
(In reply to comment #13)
> yes, "Gentoo developers" already know this because i've been talking to Pierre
> on the GD development lists ... fancy that

Wonderful, then maybe you could have responded to one of the 9 pings on this
bug... I'm afraid security folks are missing paranormal skills :P

------- Comment #15 From Nuno Lopes 2007-01-24 23:46:13 0000 -------
Pierre (the new gd maintainer) asked me to post the following comment:

For the record, I strongly recommend to do not apply all patches from debian
but from the libgd CVS.

A couple of patches listed here should not be applied at all, no matter the
distribution:
1006_western_european_fonts.patch
1004_improve_aa_lines.patch

1005_graphviz_sanitize.patch is unknown to me or maybe already committed as I
applied almost all graphiz patches sent to T. Boutell (will download it and
compare later this week).

As Vapier said earlier, he follows the list and can contact me for any further
informations. I will be happy to help gentoo to bring some order in the patch
mess.

Thanks for your work and heads up :)

------- Comment #16 From SpanKY 2007-02-07 04:26:55 0000 -------
sure, i should have kept security devs informed ... but that doesnt mean i need
some lackey who thinks he knows how to help

gd-2.0.34 in portage

------- Comment #17 From Raphael Marichez 2007-02-10 19:29:13 0000 -------
Thanks vapier, arches please test gd-2.0.34 and mark stable if appropriate ,
thanks a lot

------- Comment #18 From Christian Faulhammer 2007-02-11 09:55:08 0000 -------
x86 stable

------- Comment #19 From Tobias Scherbaum 2007-02-11 11:17:37 0000 -------
ppc stable

------- Comment #20 From René Nussbaumer 2007-02-11 21:47:36 0000 -------
Stable on hppa

------- Comment #21 From Simon Stelling (RETIRED) 2007-02-12 00:00:35 0000 -------
amd64 stable 

------- Comment #22 From Bryan Østergaard (RETIRED) 2007-02-12 00:03:03 0000 -------
Stable on IA64.

------- Comment #23 From Gustavo Zacarias (RETIRED) 2007-02-12 13:00:47 0000 -------
sparc stable.

------- Comment #24 From Bryan Østergaard (RETIRED) 2007-02-12 20:29:28 0000 -------
Stable on Alpha.

------- Comment #25 From Markus Rothe 2007-02-13 08:38:08 0000 -------
ppc64 stable

------- Comment #26 From Raphael Marichez 2007-02-13 10:30:11 0000 -------
Thanks all, time to vote for a GLSA:

i vote yes because it's an infinite loop (cpu consumption) that could be
triggered through a PHP script using gd, for example, or any other
server-oriented application calling gd.

------- Comment #27 From Tavis Ormandy (RETIRED) 2007-02-13 11:12:33 0000 -------
I would vote NO, as the impact is fairly minor.

------- Comment #28 From Matthias Geerdsen 2007-02-22 20:35:34 0000 -------
I agree with falco here

voting yes

------- Comment #29 From Raphael Marichez 2007-03-03 17:32:08 0000 -------
back to [noglsa] after having talked with the discoverer who says that it
doesn't merit an update.
Although there is a possible incrementation of the pointer on the NULL char, it
seems very very hard to obtain.
Feel free to reopen if you disagree.

First Last Prev Next    No search results available      Search page      Enter new bug