Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 160793 - net-im/centericq: Remote Buffer Overflow in LiveJournal Handling (CVE-2007-{0160,3713})
Summary: net-im/centericq: Remote Buffer Overflow in LiveJournal Handling (CVE-2007-{0...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://seclists.org/fulldisclosure/20...
Whiteboard: C2 [masked] DerCorny
Keywords: PMASKED
: 117358 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-01-07 22:46 UTC by Executioner
Modified: 2007-12-17 13:10 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Live journal buffer overflow patch (centericq-4.21.0-livejrnl-buffoverflow-fix.diff,1.07 KB, patch)
2007-01-19 15:41 UTC, Mike Pagano
no flags Details | Diff
jabber segmentation fault fix (centericq-4.21.0-jabber-segfault-fix.diff,827 bytes, patch)
2007-01-19 15:42 UTC, Mike Pagano
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Executioner 2007-01-07 22:46:00 UTC
CenterICQ contains support for LiveJournal (http://www.livejournal.com/),
  such as posting to your own blog, reading other blogs' RSS feeds, and
other
  community-related functions, such as showing whether a user has added or
  removed your own users to/from the friend list, all via a unified HTTP
  interface provided by LiveJournal. The latter functionality is vulnerable
  to a buffer overflow and possible remote code execution.



Reproducible: Didn't try
Comment 1 Executioner 2007-01-07 22:47:55 UTC
We are at centericq-4.21.0-r2, are we still vulnerable?
Comment 2 Stefan Cornelius (RETIRED) gentoo-dev 2007-01-08 18:23:14 UTC
Well, it seems like our source looks like the affected source in the advisory, so I guess we failed to dodge the bullet here and are vulnerable (i havent checked the actual exploitability, but seems reasonable enough)
Comment 3 Simon Stelling (RETIRED) gentoo-dev 2007-01-08 21:22:19 UTC
"Executioner", I see you CCd me on this bug, but I don't know why. Could you explain please? :)
Comment 4 Stefan Cornelius (RETIRED) gentoo-dev 2007-01-08 22:27:56 UTC
oh, thats what i get for not checking the maintainer! wschlich, pls have a look, thx
Comment 5 Wolfram Schlich (RETIRED) gentoo-dev 2007-01-09 00:41:57 UTC
I am not the maintainer anymore :)
See bug #81422, bug #88640, bug #116962, bug #131426, bug #138154, bug #138740 and net-im/centericq ChangeLog entry from 14 Jul 2006.
Sorry.
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-01-09 08:35:44 UTC
-dev mailed. Unless someone is willing to take over this package I propose a mask.
Comment 7 Olivier Crete (RETIRED) gentoo-dev 2007-01-09 13:23:32 UTC
seems like centericq is unmaintained upstream...
Comment 8 Olivier Crete (RETIRED) gentoo-dev 2007-01-13 20:39:17 UTC
I masked it (for net-im).
Comment 9 Simon Stelling (RETIRED) gentoo-dev 2007-01-14 02:15:20 UTC
*** Bug 117358 has been marked as a duplicate of this bug. ***
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-01-14 07:57:54 UTC
If C2 rating is correct this one needs a mask GLSA.
Comment 11 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-14 18:03:10 UTC
(In reply to comment #10)
> If C2 rating is correct this one needs a mask GLSA.
> 

it seems so. GLSA request filled.
Comment 12 Mike Pagano gentoo-dev 2007-01-19 15:37:59 UTC
Not sure if the point is moot with this being masked for removal but here's a mailing list posting with links to a patch from Debian for the buffer overflow and an additional bug fix.

http://article.gmane.org/gmane.network.centericq/4252

Comment 13 Mike Pagano gentoo-dev 2007-01-19 15:41:49 UTC
Created attachment 107457 [details, diff]
Live journal buffer overflow patch
Comment 14 Mike Pagano gentoo-dev 2007-01-19 15:42:33 UTC
Created attachment 107458 [details, diff]
jabber segmentation fault fix
Comment 15 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-22 11:56:54 UTC
(In reply to comment #12)
> Not sure if the point is moot with this being masked for removal but here's a
> mailing list posting with links to a patch from Debian for the buffer overflow
> and an additional bug fix.
> 
> http://article.gmane.org/gmane.network.centericq/4252
> 

but there was no maintainer having answered to the gentoo-dev@ call :(

Olivier, want to have a look?
Comment 16 Jakub Moc (RETIRED) gentoo-dev 2007-01-22 16:40:33 UTC
(In reply to Comment #12:

You know, we have lots of patches attached to the bugs quoted above, but with completely unresponsive upstream they are basically useless. Noone's willing to become upstream for this thing and waste more time on this.
Comment 17 Matthias Geerdsen (RETIRED) gentoo-dev 2007-01-24 20:00:40 UTC
mask GLSA 200701-20
Comment 18 Honza 2007-01-27 11:21:16 UTC
Is there any other text-based ICQ client ?
Comment 19 Olivier Crete (RETIRED) gentoo-dev 2007-01-27 15:39:32 UTC
there is gaim-text and naim at least
Comment 20 Daniel Gebhardt 2007-02-23 09:58:34 UTC
(In reply to comment #16)

> Noone's willing to become upstream for this thing 

Digging around a little I found some people are trying to keep centericq alive.

http://thread.gmane.org/gmane.network.centericq/4294

The repository of the fork is online here: 
http://repo.or.cz/w/centerim.git

So maybe its possible to keep center(icq/im) in portage somehow
Comment 21 Deleted Account 2007-03-21 14:11:19 UTC
(In reply to comment #20)
> Digging around a little I found some people are trying to keep centericq
> alive.
> 
> http://thread.gmane.org/gmane.network.centericq/4294
> 
> [...]
> 
> So maybe its possible to keep center(icq/im) in portage somehow
Dear CenterICQ-users,
the future of CenterICQ has begone and is named CenterIM! :)
Please look at the Forums under http://forums.gentoo.org/viewtopic-t-548358.html and in the Bugtracker at https://bugs.gentoo.org/show_bug.cgi?id=171682 for further informations.

please look at the "new" CenterICQ-fork: CenterIM.
The first CenterIM-ebuild (4.22.0) is available
Comment 22 Fred Thiele 2007-07-05 17:25:57 UTC
Whats up? Centericq is masked, full of void* to int cast errors (fixed them), still lacks of jabber support for amd64. And now I'm reading about centerim, which isn't in the portage tree. Can someone tell me whats up?
Comment 23 Olivier Crete (RETIRED) gentoo-dev 2007-07-05 17:36:26 UTC
CenterICQ will at some point in the near future be remove from the tree. And there is no gentoo developer who has decided to add centerim to the tree for now. maybe I'll do it at some point
Comment 24 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-08 22:43:32 UTC
(In reply to comment #23)
> CenterICQ will at some point in the near future be remove from the tree. And
> there is no gentoo developer who has decided to add centerim to the tree for
> now. maybe I'll do it at some point

centerim is in the tree, so please remove centericq.
Comment 25 Olivier Crete (RETIRED) gentoo-dev 2007-09-11 02:22:27 UTC
Its now out of the tree. You may want to amend the GLSA to reflect that and also suggest users to use finch (from the pidgin package with the ncurses use flag) or centerim.
Comment 26 Robert Buchholz (RETIRED) gentoo-dev 2007-12-17 13:10:14 UTC
Gone from the tree since September. Thanks!