Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 209903
Alias:
Product:
Component:
Status: ASSIGNED
Resolution:
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 209903 depends on: Show dependency tree
Bug 209903 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-12 19:25 0000
CVE-2008-0671 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0671):
  Stack-based buffer overflow in the add_line_buffer function in TinTin++
  1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code
  via a long chat message, related to conversion from LF to CRLF.

------- Comment #1 From Robert Buchholz 2008-02-12 19:31:21 0000 -------
Games herd, did you hear anything upstream about this?

------- Comment #2 From Robert Buchholz 2008-02-12 19:32:23 0000 -------
CVE-2008-0672 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0672):
  The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows
  remote attackers to cause a denial of service (application crash) via a YES
  message without a newline character, which triggers a NULL dereference.

CVE-2008-0673 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0673):
  TinTin++ 1.97.9 and WinTin++ 1.97.9 open files on the basis of an inbound
  file-transfer request, before the user has an opportunity to decline the
  request, which allows remote attackers to truncate arbitrary files in the top
  level of a home directory.

------- Comment #3 From Mr. Bones. 2008-02-12 19:45:35 0000 -------
I removed that version from portage.  We'll pick up normal processing on the
next version.

------- Comment #4 From Robert Buchholz 2008-02-12 20:43:28 0000 -------
I verified that all three vulnerabilities also affect our stable, so that won't
be enough. :-/

------- Comment #5 From Mr. Bones. 2008-02-12 20:59:13 0000 -------
package masked.

------- Comment #6 From Sune Kloppenborg Jeppesen 2008-02-13 17:37:34 0000 -------
maskglsa request filed.

------- Comment #7 From Mr. Bones. 2008-03-25 04:55:17 0000 -------
added tintin-1.98.0, removed all previous versions, unmasked.

------- Comment #8 From Robert Buchholz 2008-03-25 10:23:05 0000 -------
I couldn't reproduce the errors with 1.98.0, so that looks fine.

------- Comment #9 From Mr. Bones. 2009-11-23 04:28:41 0000 -------
please close this out.

------- Comment #10 From Stefan Behte 2009-11-23 17:41:14 0000 -------
A GLSA request was filed some time ago and the bug will be closed after it was
sent.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug