First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 212363
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
MITKRB5-SA-2008-001 MITKRB5-SA-2008-001 text/plain Sune Kloppenborg Jeppesen 2008-03-05 10:04 0000 20.53 KB Details
MITKRB5-SA-2008-002 MITKRB5-SA-2008-002 text/plain Sune Kloppenborg Jeppesen 2008-03-05 10:05 0000 9.80 KB Details
1.5-MITKRB5-SA-2008-001.patch 1.5-MITKRB5-SA-2008-001.patch patch Markus Ullmann 2008-03-18 20:39 0000 10.76 KB Details | Diff
1.6-MITKRB5-SA-2008-001.patch 1.6-MITKRB5-SA-2008-001.patch patch Markus Ullmann 2008-03-18 20:39 0000 10.82 KB Details | Diff
MITKRB5-SA-2008-002.patch MITKRB5-SA-2008-002.patch patch Markus Ullmann 2008-03-18 20:41 0000 1.47 KB Details | Diff
mit-krb5-1.5.3-r2.ebuild mit-krb5-1.5.3-r2.ebuild text/plain Markus Ullmann 2008-03-18 20:41 0000 2.68 KB Details
mit-krb5-1.6.3.ebuild mit-krb5/mit-krb5-1.6.3.ebuild text/plain Markus Ullmann 2008-03-18 20:42 0000 2.40 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 212363 depends on: Show dependency tree
Show dependency graph
Bug 212363 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-03-05 10:03 0000
Attaching details in a moment.

------- Comment #1 From Sune Kloppenborg Jeppesen 2008-03-05 10:04:49 0000 -------
Created an attachment (id=145336) [edit]
MITKRB5-SA-2008-001

------- Comment #2 From Sune Kloppenborg Jeppesen 2008-03-05 10:05:10 0000 -------
Created an attachment (id=145337) [edit]
MITKRB5-SA-2008-002

------- Comment #3 From Robert Buchholz 2008-03-05 10:25:46 0000 -------
I'll rate this classified because MIT asked not to publish their drafts.

------- Comment #4 From Robert Buchholz 2008-03-09 12:36:48 0000 -------
Markus, please prepare an ebuild using the patches inside the two advisories
and attach it to this bug. Do not commit anything to CVS or make details about
this vulnerability public.

------- Comment #5 From Robert Buchholz 2008-03-14 21:53:42 0000 -------
Adding Wulf.

------- Comment #6 From Robert Buchholz 2008-03-18 01:58:53 0000 -------
In case you attach ebuilds, please include the patches mentioned in bug 199205.

Seeing that this will become public today, we might as well bump to the new
release which will include patches for all these vulnerabilities.

------- Comment #7 From Markus Ullmann 2008-03-18 20:39:07 0000 -------
Created an attachment (id=146508) [edit]
1.5-MITKRB5-SA-2008-001.patch

------- Comment #8 From Markus Ullmann 2008-03-18 20:39:46 0000 -------
Created an attachment (id=146509) [edit]
1.6-MITKRB5-SA-2008-001.patch

------- Comment #9 From Markus Ullmann 2008-03-18 20:41:07 0000 -------
Created an attachment (id=146510) [edit]
MITKRB5-SA-2008-002.patch

------- Comment #10 From Markus Ullmann 2008-03-18 20:41:49 0000 -------
Created an attachment (id=146511) [edit]
mit-krb5-1.5.3-r2.ebuild

------- Comment #11 From Markus Ullmann 2008-03-18 20:42:41 0000 -------
Created an attachment (id=146512) [edit]
mit-krb5/mit-krb5-1.6.3.ebuild

------- Comment #12 From Markus Ullmann 2008-03-18 20:43:45 0000 -------
also whoever sent those advisories in, please break a bone there for sending in
patches with broken whitespaces... could have done something else than this the
last 1 1/2 hours ;)

------- Comment #13 From Markus Ullmann 2008-03-18 20:45:56 0000 -------
(as sent to me by rbu)

Arch Security Liaisons, please test the attached ebuild and report it 
stable on this bug.
Target keywords : "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 release 
s390 sh sparc x86"

CC'ing current Liaisons:
   alpha : ferdy
   amd64 : welp
    hppa : jer
     ppc : dertobi123
   ppc64 : corsair
 release : pva
   sparc : fmccor
     x86 : opfer

------- Comment #14 From Tobias Scherbaum 2008-03-18 21:21:30 0000 -------
Debian just released DSA 1524-1, so i guess we can this opened and committet.

------- Comment #15 From Markus Ullmann 2008-03-18 21:36:28 0000 -------
okay, update... scratch the 1.5 release. a fellow just updated servers and all
work fine with 1.6, so we can go straight to that version

------- Comment #16 From Pierre-Yves Rofes 2008-03-18 22:10:02 0000 -------
okay, this is public now, so removing sec liaisons, adding arches, and filing
GLSA request. if everyone's responsive enough, we shouldn't be too late :)
target for stabilisation is app-crypt/mit-krb5-1.6.3, just commited by jokey.
keywords "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc x86"

------- Comment #17 From Jeroen Roovers 2008-03-18 22:13:16 0000 -------
(In reply to comment #16)
> if everyone's responsive enough, we shouldn't be too late :)

OK, here goes:

> target for stabilisation is app-crypt/mit-krb5-1.6.3, just commited by jokey.

It hasn't been committed yet! :)

------- Comment #18 From Tobias Scherbaum 2008-03-18 22:15:03 0000 -------
ppc stable

------- Comment #19 From Jeroen Roovers 2008-03-18 22:15:52 0000 -------
(In reply to comment #17)
> It hasn't been committed yet! :)

Ah, it's there now.

------- Comment #20 From Tobias Scherbaum 2008-03-18 22:17:34 0000 -------
fixing priority which i set back to p2 for whatever reason ...

------- Comment #21 From Jeroen Roovers 2008-03-19 00:32:20 0000 -------
Stable for HPPA.

------- Comment #22 From Robert Buchholz 2008-03-19 00:50:38 0000 -------
public via
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt

------- Comment #23 From Christian Faulhammer 2008-03-19 08:08:45 0000 -------
x86 stable

------- Comment #24 From Markus Rothe 2008-03-19 11:39:28 0000 -------
app-crypt/mit-krb5-1.6.3 stable on ppc64

------- Comment #25 From Raúl Porcel 2008-03-19 14:19:12 0000 -------
alpha/ia64/sparc stable

------- Comment #26 From Markus Ullmann 2008-03-19 16:47:47 0000 -------
Stable on amd64/arm

------- Comment #27 From Robert Buchholz 2008-03-24 19:40:37 0000 -------
GLSA 200803-31

First Last Prev Next    No search results available      Search page      Enter new bug