First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 158219
Alias:
Product:
Component:
Status: RESOLVED
Resolution: INVALID
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 158219 depends on: Show dependency tree
Show dependency graph
Bug 158219 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-12-15 07:41 0000
Upstream [1] says:

"An update has been issued on August 29,2006 to solve this vulnerability. "

i couldn't find the fixed version number.

Andrej, please can you bump a fixed version? thanks.

http://www.bitdefender.com/KB323-en--cevakrnl.xmd-vulnerability.html

------- Comment #1 From Andrej Kacian (RETIRED) 2006-12-25 07:50:50 0000 -------
I wonder why haven't I noticed this before. Quoting the URL above:

"An update has been issued on August 29,2006 to solve this vulnerability. The
update has been delivered immediately to all BitDefender users through regular
automatic update mechanism, so no user action is required."

Thus, there's no need for a version bump, as this has been fixed for every user
who regularly updates via "bdc --update", as cevakrnl.xmd file is one of those
being updated this way.

I will be adding 7.1 later today, just after I figure out what to do with a
file collision that happens with this version. It's up to you guys if you want
to close this bug by having 7.1 added (since cevakrnl.xmd shipped with it is
fixed).

------- Comment #2 From Andrej Kacian (RETIRED) 2007-01-01 11:25:37 0000 -------
Just an update - I haven't found a good way to handle collision-protect for
7.1. It is in the tree, but masked. Perhaps someone can help me out here?

To reproduce the issue at hand, merge 7.0.1-r1, issue "bdc --update" and merge
7.1 (after unmasking it) with FEATURES="collision-protect"

------- Comment #3 From Sune Kloppenborg Jeppesen 2007-01-06 12:23:35 0000 -------
Adding herd to get some response.

------- Comment #4 From Raphael Marichez 2007-01-12 22:21:32 0000 -------
Antivirus team, please advise or we will have to take some nasty decision like
a temporary masking GLSA or so :(
Thanks in advance.

------- Comment #5 From Andrej Kacian (RETIRED) 2007-01-13 01:10:41 0000 -------
I'm afraid I'm the only one regularly active on antivirus team, and I'm out of
ideas how to handle bitdefender-console update without file collisions.

7.1 is in the tree, package.masked. To reproduce the trouble I'm having, merge
7.0.1-r1, update malware database with "bdc --update", and update to 7.1 with
FEATURES="collision-protect".

BTW, I repeat that anyone who does "bdc --update" with 7.0.1 (or earlier) gets
updated and non-vulnerable cevakrnl.xmd file.

------- Comment #6 From Raphael Marichez 2007-01-13 20:54:23 0000 -------
> BTW, I repeat that anyone who does "bdc --update" with 7.0.1 (or earlier) gets
> updated and non-vulnerable cevakrnl.xmd file.


Thanks for all your answers Ticho. Unfortunately i can't help you on the
collision issue.

Perhaps we could emit a GLSA telling to do a "bdc --update", but i really hope
that our bitdefender-console users have already done that at least once since
august.

So i propose to close that bug as invalid. Security team, please comment. (I'll
close the bug as invalid within 7 days without any anwser.)

------- Comment #7 From Raphael Marichez 2007-03-03 13:25:36 0000 -------
obsolete and invalid (considering the Gentoo Security scope, not anti-virus
scope) as said earlier.

Feel free to reopen if you disagree.

------- Comment #8 From Andrej Kacian (RETIRED) 2007-04-08 22:58:32 0000 -------
Just for reference, 7.1 is now unmasked in the tree, after working around the
collision issue.

First Last Prev Next    No search results available      Search page      Enter new bug