First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 225851
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matthias Geerdsen <vorlon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
build.log freetype 2.3.6 build log text/plain Renato Alves 2008-06-15 13:20 0000 95.64 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 225851 depends on: Show dependency tree
Bug 225851 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-06-11 09:18 0000
Multiple vulnerabilities have been found in freetype2

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=715
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=716
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=717

idefense reports the following in all three advisories:
<quote>
Exploitation of this vulnerability results in the execution of arbitrary code
with the privileges of the application using the library. Since FreeType2 is a
library and not a standalone application, the exploitation vector will vary.
iDefense Labs verified that local privilege escalation was possible via the
X.Org Xserver.</quote>

------- Comment #1 From Matthias Geerdsen 2008-06-11 09:19:33 0000 -------
fonts herd, please provide an updated ebuild

------- Comment #2 From Peter Alfredsen 2008-06-11 09:42:53 0000 -------
I(In reply to comment #1)
> fonts herd, please provide an updated ebuild

Please check your local portage rsync mirror.

------- Comment #3 From Matthias Geerdsen 2008-06-11 09:45:08 0000 -------
sorry, loki_val pointed out that it was already in the tree

arches, please test media-libs/freetype-2.3.6 and mark stable if possible

target KEYWORDS="alpha amd64 arm hppa ia64 m68k ~mips ppc ppc64 s390 sh sparc
~sparc-fbsd x86 ~x86-fbsd"

------- Comment #4 From Christian Faulhammer 2008-06-11 14:05:31 0000 -------
x86 stable

------- Comment #5 From Friedrich Oslage 2008-06-11 16:27:54 0000 -------
sparc stable

------- Comment #6 From Raúl Porcel 2008-06-11 18:41:50 0000 -------
alpha/ia64 stable

------- Comment #7 From Steve Dibb 2008-06-11 20:13:43 0000 -------
amd64 stable

------- Comment #8 From Brent Baude 2008-06-11 21:08:58 0000 -------
ppc64 done

------- Comment #9 From Ryan Hill 2008-06-12 00:54:27 0000 -------
it should be okay to remove 2.1.10-r3 now.  i kept it in the tree because some
people were getting crashes with newer versions, but we fixed that with some
eclass changes a while back.

------- Comment #10 From Jeroen Roovers 2008-06-12 03:27:02 0000 -------
Stable for HPPA.

------- Comment #11 From Tobias Scherbaum 2008-06-13 15:15:35 0000 -------
ppc stable

------- Comment #12 From Renato Alves 2008-06-15 13:20:39 0000 -------
Created an attachment (id=156889) [edit]
freetype 2.3.6 build log

emerge failed for me -> x86

build log attached

Portage 2.1.4.4 (default-linux/x86/2007.0, gcc-4.1.2, glibc-2.6.1-r0,
2.6.24-gentoo-r8 i686)
=================================================================
System uname: 2.6.24-gentoo-r8 i686 Intel(R) Pentium(R) M processor 2.00GHz
Timestamp of tree: Sun, 15 Jun 2008 12:30:01 +0000
ccache version 2.4 [enabled]
app-shells/bash:     3.2_p33
dev-java/java-config: 1.3.7, 2.1.6
dev-lang/python:     2.4.4-r13
dev-python/pycrypto: 2.0.1-r6
dev-util/ccache:     2.4-r7
sys-apps/baselayout: 1.12.12
sys-apps/sandbox:    1.2.18.1-r2
sys-devel/autoconf:  2.13, 2.61-r1
sys-devel/automake:  1.4_p6, 1.5, 1.7.9-r1, 1.9.6-r2, 1.10.1
sys-devel/binutils:  2.18-r1
sys-devel/gcc-config: 1.4.0-r4
sys-devel/libtool:   1.5.26
virtual/os-headers:  2.6.23-r3
ACCEPT_KEYWORDS="x86"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-march=pentium-m -O2 -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config
/usr/kde/3.5/shutdown /usr/share/config"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf
/etc/gconf /etc/revdep-rebuild /etc/terminfo /etc/texmf/web2c
/etc/udev/rules.d"
CXXFLAGS="-march=pentium-m -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="ccache collision-protect distlocks metadata-transfer parallel-fetch
sandbox sfperms strict unmerge-orphans userfetch"
GENTOO_MIRRORS="http://darkstar.ist.utl.pt/gentoo/
http://ftp.dei.uc.pt/pub/linux/gentoo/ http://cesium.di.uminho.pt/pub/gentoo/"
LANG="en_US.UTF-8"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress
--force --whole-file --delete --stats --timeout=180 --exclude=/distfiles
--exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/portage/local/layman/science /usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="X alsa bzip2 cli cracklib crypt cups dri firefox fortran gdbm gif gpm
iconv ipv6 isdnlog jpeg midi mudflap ncurses nptl nptlonly opengl openmp pcre
perl png pppd python readline reflection sdl session spl sse sse2 ssl tcpd tiff
truetype unicode x86 xorg zlib" ALSA_CARDS="intel8x0 intel8x0m"
ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file
hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route
share shm softvol" APACHE2_MODULES="actions alias auth_basic auth_digest
authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile
authz_host authz_owner authz_user autoindex cache dbd deflate dir disk_cache
env expires ext_filter file_cache filter headers ident imagemap include info
log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp
proxy_balancer proxy_connect proxy_ftp proxy_http rewrite setenvif speling
status unique_id userdir usertrack vhost_alias" APACHE2_MPMS="worker"
ELIBC="glibc" INPUT_DEVICES="keyboard mouse synaptics" KERNEL="linux"
LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses
text" USERLAND="GNU" VIDEO_CARDS="fbdev fglrx vesa vga radeon"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, LDFLAGS,
LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS

------- Comment #13 From Ryan Hill 2008-06-16 04:45:04 0000 -------
try rebuilding libtool.

------- Comment #14 From Peter Volkov 2008-06-16 16:40:23 0000 -------
Fixed in release snapshot.

------- Comment #15 From Renato Alves 2008-06-19 21:24:57 0000 -------
(In reply to comment #13)
> try rebuilding libtool.
> 

Still doesn't build. The error is the same
revdep-rebuild finds nothing...
sync as of Thu Jun 19 21:20:34 UTC 2008

------- Comment #16 From Renato Alves 2008-06-19 21:56:24 0000 -------
(In reply to comment #15)
> (In reply to comment #13)
> > try rebuilding libtool.
> > 
> 
> Still doesn't build. The error is the same
> revdep-rebuild finds nothing...
> sync as of Thu Jun 19 21:20:34 UTC 2008
> 

Nevermind... ccache was the culprit. cleaning ccache solved the problem

------- Comment #17 From Robert Buchholz 2008-06-24 00:03:18 0000 -------
GLSA 200806-10

------- Comment #18 From Steve Schmechel 2008-07-05 15:31:59 0000 -------
(In reply to comment #17)
> GLSA 200806-10
> 

All the CVE's state that FreeType2 has vulnerabilities.  
The GLSA's scope is applied to 1.X series also.  Is this correct?

TexLive has dependencies on =media-libs/freetype-1* 
I don't think this will be easy to change any time soon.

Is there really a problem with the 1.x code?
If there is, could a backported FreeType-1.x fix be made available?

------- Comment #19 From Ryan Hill 2008-07-05 22:30:23 0000 -------
the CVE's specifically say Freetype2, so I don't believe 1.* is affected. 
however i don't speak for the security team.

------- Comment #20 From Robert Buchholz 2008-07-06 22:03:27 0000 -------
Are we still maintaining those? Whoops, this bug needs to be reopened then.

Analysis by our friends at RedHat yielded that 1.X is also affected, see this
for a patch:
http://cvs.fedoraproject.org/viewcvs/devel/freetype1/freetype-1.4pre-CVE-2008-1808.patch?rev=1.1&view=auto

------- Comment #21 From Peter Alfredsen 2008-07-06 22:39:38 0000 -------
+*freetype-1.4_pre20080316-r1 (06 Jul 2008)
+
+  06 Jul 2008; Peter Alfredsen <loki_val@gentoo.org>
+  +files/freetype-1.4_pre20080316-CVE-2008-1808.patch,
+  +freetype-1.4_pre20080316-r1.ebuild:
+  Revbump for CVE-2008-{1806,1807,1808}, bug #225851.
+

------- Comment #22 From Robert Buchholz 2008-07-06 23:50:44 0000 -------
Arches, please test and mark stable:
=media-libs/freetype-1.4_pre20080316-r1
Target keywords : "alpha amd64 arm hppa ia64 m68k ppc ppc64 s390 sh sparc x86"

------- Comment #23 From Brent Baude 2008-07-07 02:41:09 0000 -------
ppc and ppc64 -r1 done now.

------- Comment #24 From Brent Baude 2008-07-07 03:01:05 0000 -------
removing arches

------- Comment #25 From Ferris McCormick 2008-07-07 12:16:25 0000 -------
Sparc stable for freetype-1.4_pre20080316-r1 , too.

------- Comment #26 From Markus Meier 2008-07-07 21:05:52 0000 -------
amd64/x86 stable

------- Comment #27 From Jeroen Roovers 2008-07-07 23:38:40 0000 -------
Both stable for HPPA now.

------- Comment #28 From Raúl Porcel 2008-07-08 12:45:25 0000 -------
alpha/ia64 stable

------- Comment #29 From Steve Schmechel 2008-07-11 18:21:03 0000 -------
(In reply to comment #22)
> Arches, please test and mark stable:
> =media-libs/freetype-1.4_pre20080316-r1
> Target keywords : "alpha amd64 arm hppa ia64 m68k ppc ppc64 s390 sh sparc x86"
> 

Can we get the GSLA vulnerable/unaffected versions updated so that glsa-check
does not keep identifying freetype-1.4_pre20080316-r1 as an issue?

------- Comment #30 From Robert Buchholz 2008-07-11 18:58:48 0000 -------
(In reply to comment #29)
> Can we get the GSLA vulnerable/unaffected versions updated so that glsa-check
> does not keep identifying freetype-1.4_pre20080316-r1 as an issue?

Yes, we will. Please note that this will require an updated version of the GLSA
to be sent out.

------- Comment #31 From Jeroen Roovers 2008-08-05 16:29:32 0000 -------
*** Bug 233962 has been marked as a duplicate of this bug. ***

------- Comment #32 From Jeroen Roovers 2008-08-22 18:33:32 0000 -------
*** Bug 235412 has been marked as a duplicate of this bug. ***

------- Comment #33 From Pierre-Yves Rofes 2008-09-06 20:36:01 0000 -------
xml fixed (added 1.4_pre20080316-r1 as unaffected). No errata will be released
as users were safe anyway. Sorry for the delay.

First Last Prev Next    No search results available      Search page      Enter new bug