First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 72681
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 72681 depends on: Show dependency tree
Show dependency graph
Bug 72681 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-11-27 16:52 0000
FL uses an older version than we have in Portage, but we might be affected
anyway.

Snipped from FL bug:

I've discovered more vulnerabilities in Imlib (1.9.13). In particular, it
appears to be affected by a variant of Chris Evans' libXpm flaw #1
(CAN-2004-0782, see http://scary.beasts.org/security/CESA-2004-003.txt). Look
at the attached image, it kills ee on my 7.3.

------- Comment #1 From Matthias Geerdsen 2004-11-29 01:10:12 0000 -------
The patch in the RedHat bug is for .13, but seems to fix stuff present in .14
too.
Then there is this Fedora bug
https://bugzilla.fedora.us/show_bug.cgi?id=2051#c11
with patches provided by Pavel Kankovsky. The patch for .14 seems to be mainly
the same as we have in portage atm, but someone might want to check out the
patches for .13, which seem to patch stuff present in .14 too.

------- Comment #2 From Matthias Geerdsen 2004-11-30 03:04:00 0000 -------
gnome team, please verify, advise and apply patches if appropriate

patches can be found in the two bug reports mentioned in the above comments

------- Comment #3 From Thierry Carrez (RETIRED) 2004-12-02 01:41:18 0000 -------
Could not reproduce this, but I don't know what really makes use of imlib...

------- Comment #4 From foser (RETIRED) 2004-12-02 05:55:03 0000 -------
gnome1 apps probably.

------- Comment #5 From Carsten Lohrke 2004-12-03 16:45:02 0000 -------
>Could not reproduce this, but I don't know what really makes use of imlib...
>gnome1 apps probably.

a wide range of apps does:

x11-plugins/gkrellm-radio
x11-plugins/gkrellm-alltraxclock
x11-plugins/epplets
x11-plugins/gkrellmoon
x11-plugins/gkrellsun
x11-plugins/gkrellm-console
x11-plugins/gkrellm-mailwatch
x11-plugins/gkrellm-bfm
x11-plugins/gkrellmouse
x11-plugins/gkrellscore
x11-plugins/gkrellshoot
x11-libs/libast
x11-misc/bbrb
x11-misc/pogo
x11-misc/e16menuedit
x11-misc/idesk
x11-misc/wmakerconf
x11-misc/e16keyedit
www-client/w3m
www-client/w3mmee
www-client/w3m-m17n
games-strategy/freeciv
x11-terms/mlterm
app-admin/gkrellm
x11-themes/gtk-engines
x11-themes/qtpixmap
gnome-base/gnome-libs
app-i18n/minichinput
app-i18n/chinput
app-misc/dfm
app-misc/endeavour
kde-base/kdegraphics
mail-client/balsa
mail-client/sylpheed-claws
mail-client/sylpheed
media-gfx/iv
media-gfx/qiv
media-gfx/xzgv
media-gfx/frontline
media-gfx/digikam
media-gfx/gphoto
media-gfx/gimageview
net-irc/bitchx
net-www/amaya
media-libs/fnlib
net-im/amsn
net-im/gnophone
net-libs/jaimlib
games-board/eboard
app-office/magicpoint
x11-wm/fvwm
x11-wm/qvwm
x11-wm/xfce
x11-wm/icewm
x11-wm/sawfish
x11-wm/enlightenment
dev-lang/R
dev-lang/entity
dev-ruby/ruby-gdkimlib
dev-ruby/ruby-gnome
dev-python/pygtk
dev-python/gnome-python
app-editors/zoinks
media-sound/yconsole
media-video/kino
media-video/motioneye
media-video/camserv
app-sci/scigraphica
games-kids/lletters
games-kids/stickers

------- Comment #6 From Joe McCann (RETIRED) 2004-12-04 14:39:51 0000 -------
I have added imlib-1.9.14-r3 to cvs ( with the patch from
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=138516 ). That combined
with our patch takes care of the overflow issues. Archs please test and mark
stable.

------- Comment #7 From Mike Doty 2004-12-04 15:23:39 0000 -------
stable on amd64

------- Comment #8 From Jochen Maes (RETIRED) 2004-12-05 00:36:35 0000 -------
stable on ppc

------- Comment #9 From SpanKY 2004-12-05 01:29:54 0000 -------
arm/hppa/ia64 stable

------- Comment #10 From Markus Rothe 2004-12-05 01:31:21 0000 -------
stable on ppc64

------- Comment #11 From SpanKY 2004-12-05 01:32:39 0000 -------
err didnt mean to close

------- Comment #12 From Ferris McCormick 2004-12-05 07:37:54 0000 -------
Stable for sparc.

------- Comment #13 From Bryan Østergaard (RETIRED) 2004-12-05 08:05:11 0000 -------
Stable on alpha.

------- Comment #14 From Stephen Becker (RETIRED) 2004-12-05 19:10:32 0000 -------
stable on mips

------- Comment #15 From Thierry Carrez (RETIRED) 2004-12-06 02:07:32 0000 -------
GLSA drafted

------- Comment #16 From Thierry Carrez (RETIRED) 2004-12-06 07:58:22 0000 -------
GLSA 200412-03

First Last Prev Next    No search results available      Search page      Enter new bug