First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 68375
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Hanno Boeck <hanno@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
plasmaroo:
 
koon: ()

Filename Description Type Creator Created Size Actions
CAN-2004-0816.patch Patch patch Tim Yamin (RETIRED) 2004-10-21 11:36 0000 1.65 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 68375 depends on: Show dependency tree
Bug 68375 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-21 04:20 0000
http://www.suse.de/de/security/2004_37_kernel.html
contains the details.
CVE is CAN-2004-0816

Although this only affects kernels <2.6.8, we still have ebuilds around where the latest ones are 2.6.7 (e.g. hardened-dev-sources).

------- Comment #1 From Tim Yamin (RETIRED) 2004-10-21 11:36:04 0000 -------
Created an attachment (id=42326) [edit]
Patch

------- Comment #2 From Tim Yamin (RETIRED) 2004-10-21 11:37:17 0000 -------
Ok, all done. The following externally maintained sources remain, adding
maintainers to the CC.

hardened-dev-sources - Adding hardened@gentoo.org.
mips-sources - Adding kumba@gentoo.org.
rsbac-dev-sources - Adding kang@gentoo.org.

------- Comment #3 From Guillaume Destuynder (RETIRED) 2004-10-22 04:57:41 0000 -------
CAN-2004-0816 => Done for rsbac-dev-sources.

------- Comment #4 From Jeremy Huddleston (RETIRED) 2004-10-30 02:55:42 0000 -------
this should be added to a revbump of g-d-s-2.6.7 as well for sparc as it can't
use >=2.6.8

------- Comment #5 From Ed Grimm 2004-11-01 01:36:22 0000 -------
It applies, compiles, and boots without error on hardened-dev-sources-2.6.5-r5.
 Personally, I feel that it would at least rate a ~arch ebuild, especially
since y'all apparently felt that this was sufficient to pull all
hardened-dev-sources ebuilds, rather than merely hard-masking them.

------- Comment #6 From Sune Kloppenborg Jeppesen 2004-11-01 23:56:36 0000 -------
hardened-dev-sources seems to be patched.

Thanks for patching Joshua but please remember to comment on the bug.

------- Comment #7 From Thierry Carrez (RETIRED) 2004-11-09 08:33:49 0000 -------
Moving to newly-created kernel-specific category

------- Comment #8 From Thierry Carrez (RETIRED) 2004-11-09 08:37:13 0000 -------
I think it's ready for a GLSA, as mips-sources is not required to issue the
GLSA.

kumba: please apply patch to mips-sources to benefit from GLSA

------- Comment #9 From Tim Yamin (RETIRED) 2004-11-09 08:44:47 0000 -------
This is getting augmented with bug #62524 and bug #68421 for a GLSA...

------- Comment #10 From Sune Kloppenborg Jeppesen 2004-11-17 13:00:17 0000 -------
*** Bug 71586 has been marked as a duplicate of this bug. ***

------- Comment #11 From George L. Emigh 2004-11-17 13:16:20 0000 -------
I am seeing indications of this problem in gentoo-dev-sources-2.6.9-r1 and -r4

George

------- Comment #12 From Joshua Kinard 2004-11-19 18:08:49 0000 -------
mips-sources updated.

------- Comment #13 From Tim Yamin (RETIRED) 2005-01-15 14:36:43 0000 -------
All kernels fixed, closing bug; notifications are being migrated away from
GLSAs for kernels, more news coming soon so stay tuned :-]

------- Comment #14 From Robert Buchholz 2009-05-03 13:19:33 0000 -------
for ipv4:
http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=1fe7d5a3b74732a0f168c18aa64249bcc280fbb8

for the ipv6 part:
http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=8bd22e22e883efb5f56d9045f631f792784a5e4c

First Last Prev Next    No search results available      Search page      Enter new bug