Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 264613 - <kde-base/kopete-3.5.10-r4: contact description DOS (CVE-2008-4776)
Summary: <kde-base/kopete-3.5.10-r4: contact description DOS (CVE-2008-4776)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B3 [noglsa]
Keywords:
Depends on: CVE-2008-4776 264611 271889
Blocks:
  Show dependency tree
 
Reported: 2009-04-02 11:35 UTC by Robert Buchholz (RETIRED)
Modified: 2011-01-02 19:17 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
kopete-libgadu-CVE-2008-4776.patch (kopete-libgadu-CVE-2008-4776.patch,1.10 KB, patch)
2009-05-25 19:29 UTC, Robert Buchholz (RETIRED)
no flags Details | Diff
Proposed ebuild (kopete-3.5.10-r3.ebuild,4.05 KB, text/plain)
2009-05-27 10:33 UTC, Mieszko Ślusarczyk
no flags Details
Testing kopete-3.5.9-r3 ebuild (kopete-3.5.9-r3.ebuild,4.17 KB, text/plain)
2009-07-10 16:12 UTC, Jorge Manuel B. S. Vicetto (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-04-02 11:35:20 UTC
kopete bundles libgadu

+++ This bug was initially created as a clone of Bug #244888 +++

CVE-2008-4776 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4776):
  libgadu before 1.8.2 allows remote servers to cause a denial of
  service (crash) via a contact description with a large length, which
  triggers a buffer over-read.
Comment 1 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-05-15 02:46:39 UTC
I just committed an updated ebuild which forcibly disables gadu. Unfortunately kopete won't support the system gadu.
Comment 2 Mieszko Ślusarczyk 2009-05-21 23:05:14 UTC
(In reply to comment #1)
> I just committed an updated ebuild which forcibly disables gadu. Unfortunately
> kopete won't support the system gadu.
> 

Great. Now kopete doesn't support gadu at all. Can you patch bundled libgadu instead of just disabling it?
Comment 3 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-05-25 12:49:29 UTC
(In reply to comment #2)
> (In reply to comment #1)
> > I just committed an updated ebuild which forcibly disables gadu. Unfortunately
> > kopete won't support the system gadu.
> > 
> 
> Great. Now kopete doesn't support gadu at all. Can you patch bundled libgadu
> instead of just disabling it?

Kopete bundled libgadu is a fork from the 1.5 release. If you can get a working patch, we'll apply it, otherwise we'll focus on getting KDE4 marked stable.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2009-05-25 19:29:07 UTC
Created attachment 192434 [details, diff]
kopete-libgadu-CVE-2008-4776.patch

It seems this patch is sufficient to fix the security bug. I could not verify functionality against a gadu server.

Mieszko, if you can apply and test the patch, that would be very helpful.
Comment 5 Mieszko Ślusarczyk 2009-05-27 10:33:41 UTC
Created attachment 192575 [details]
Proposed ebuild

Proposed patch works, and I've made ebuild using it, which also works;)
Comment 6 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2009-05-27 18:58:57 UTC
*** Bug 264611 has been marked as a duplicate of this bug. ***
Comment 7 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2009-05-27 19:34:35 UTC
fixed in kopete-3.5.10-r4, which is soon-to-be-stabilized. This can be closed
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2009-05-27 21:09:17 UTC
(In reply to comment #7)
> fixed in kopete-3.5.10-r4, which is soon-to-be-stabilized. This can be closed
> 

Thanks for the effort and fast fix. But please let the security team decide how to handle security bugs and when to close them.

Okay, so kopete-3.5.10-r4 is fixed. Our usual process would now suggest stabilization. Are there any regressions or is it ready to be stabilized?
Comment 9 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2009-05-27 21:15:12 UTC
kopete-3.5.10-r4 can't go for stabilization, it will go along with the other kde-3.5.10 packages. I'll reply here when i'll do this (which i plan to do it really soon).  Just for the record, bug 245954 is the tracker for kde3
Comment 10 Robert Buchholz (RETIRED) gentoo-dev 2009-05-28 09:03:34 UTC
Please update us when you have a timeline for stabilization.
Comment 11 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2009-05-30 17:16:58 UTC
I have opened stabilization bug for kde 3.5.10, adding it in depend buglist
Comment 12 Robert Buchholz (RETIRED) gentoo-dev 2009-07-10 13:33:43 UTC
kde 3.5.10 stabling seems to progress rather slow. do you have any input from arches or is it feasible to stable a patched kopete 3.5.9 in the meantime?
Comment 13 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-07-10 15:04:35 UTC
(In reply to comment #12)
> kde 3.5.10 stabling seems to progress rather slow. do you have any input from
> arches or is it feasible to stable a patched kopete 3.5.9 in the meantime?

Robert,

looking at the tree, seems like alpha and sparc are the last 2 stable arches missing 3.5.10. IIRC, alpha should be having issues with the latest Xorg and sparc has issues with qt-qwebkit.
Comment 14 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-07-10 16:12:04 UTC
Created attachment 197466 [details]
Testing kopete-3.5.9-r3 ebuild
Comment 15 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-07-10 16:13:55 UTC
I've added the CVE patch to the above ebuild. It builds here, but I don't have gadu access. Can anyone test it with gadu?

@alpha / @sparc:

If you still can't do 3.5.10, would you be willing to test and stable the above instead?
Comment 16 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-07-12 15:29:17 UTC
(In reply to comment #13)
> Robert,
> 
> looking at the tree, seems like alpha and sparc are the last 2 stable arches
> missing 3.5.10. IIRC, alpha should be having issues with the latest Xorg and
> sparc has issues with qt-qwebkit.

Please ignore the above comment as it's related to KDE-4 and not KDE-3.5.
In the meanwhile Raúl has stabled 3.5.10 in both alpha and sparc.
Comment 17 Theo Chatzimichos (RETIRED) archtester gentoo-dev Security 2010-01-23 15:32:32 UTC
KDE 3 is not in tree any more. CC us again if you need anything. thanks
Comment 18 Tim Sammut (RETIRED) gentoo-dev 2011-01-02 04:56:24 UTC
GLSA Vote: no.
Comment 19 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2011-01-02 18:59:54 UTC
GLSA Vote: no.
Comment 20 Tim Sammut (RETIRED) gentoo-dev 2011-01-02 19:17:31 UTC
(In reply to comment #19)
> GLSA Vote: no.
> 

Thanks; closing noglsa.