First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 77992
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jean-François Brunette (RETIRED) <formula7@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 77992 depends on: Show dependency tree
Bug 77992 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-01-14 09:56 0000
Andrew V. Samoilov has noticed that several bugfixes which were applied to the
source by upstream developers of mc, the midnight commander, a file browser and
manager, were not backported to the current version of mc that Debian ships in
their stable release. The Common Vulnerabilities and Exposures Project
identifies the following vulnerabilities:

    * CAN-2004-1004

      Multiple format string vulnerabilities
    * CAN-2004-1005

      Multiple buffer overflows
    * CAN-2004-1009

      One infinite loop vulnerability
    * CAN-2004-1090

      Denial of service via corrupted section header
    * CAN-2004-1091

      Denial of service via null dereference
    * CAN-2004-1092

      Freeing unallocated memory
    * CAN-2004-1093

      Denial of service via use of already freed memory
    * CAN-2004-1174

      Denial of service via manipulating non-existing file handles
    * CAN-2004-1175

      Unintended program execution via insecure filename quoting
    * CAN-2004-1176

      Denial of service via a buffer underflow

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-01-14 10:10:56 0000 -------
Heinrich please verify and advise.

------- Comment #2 From Thierry Carrez (RETIRED) 2005-02-02 02:35:24 0000 -------
lanius: if you think you won't have time for such a large-scale patch, should
we mask mc ? Or do you think you can find another maintainer/herd to help you ?

------- Comment #3 From Heinrich Wendel (RETIRED) 2005-02-12 04:23:25 0000 -------
I had to apply parts of/the complete patches of:

CAN-2004-1004
CAN-2004-1005
CAN-2004-1092
CAN-2004-1176

mc-4.6.0-r13 marked: amd64,x86

mc-4.6.0-r13 missing keywords: ~alpha ~arm ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sparc


------- Comment #4 From Sune Kloppenborg Jeppesen 2005-02-12 13:19:28 0000 -------
Thx Heinrich.

Arches please test and mark stable.

------- Comment #5 From Michael Hanselmann (hansmi) (RETIRED) 2005-02-12 13:36:36 0000 -------
Stable on ppc.

------- Comment #6 From Markus Rothe 2005-02-13 00:42:13 0000 -------
stable on ppc64

------- Comment #7 From Bryan Østergaard (RETIRED) 2005-02-13 02:55:19 0000 -------
Stable on alpha.

------- Comment #8 From Jason Wever (RETIRED) 2005-02-13 09:41:22 0000 -------
Stable on SPARC.

------- Comment #9 From Thierry Carrez (RETIRED) 2005-02-15 01:24:31 0000 -------
lanius: this wasn't keyworded x86 and amd64.

------- Comment #10 From Heinrich Wendel (RETIRED) 2005-02-15 06:04:52 0000 -------
sorry, now it is

------- Comment #11 From Sune Kloppenborg Jeppesen 2005-02-17 13:08:05 0000 -------
Thx everyone

GLSA 200502-24

mips please remember to mark stable.

------- Comment #12 From Hardave Riar (RETIRED) 2005-02-19 14:47:44 0000 -------
Stable on mips.

First Last Prev Next    No search results available      Search page      Enter new bug