First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 96727
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 96727 depends on: Show dependency tree
Show dependency graph
Bug 96727 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-06-21 13:03 0000
The telnetd server program in Heimdal has buffer overflows in the function
getterminaltype, which may lead to remote code execution. 

0.6.5 and 0.7 fixes this problem.

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-06-21 13:07:57 0000 -------
kerberos please advise. 

------- Comment #2 From Seemant Kulleen (RETIRED) 2005-06-21 13:09:57 0000 -------
will fix, stay tuned

------- Comment #3 From Seemant Kulleen (RETIRED) 2005-06-21 14:35:15 0000 -------
ok, so the vulnerability is valid -- I have added 0.6.5 into portage, testing
for EVERYONE.  I will stable amd64 in about 12 hours or so -- arch teams, please
note very carefully:

The following packages need to go stable *at the same time* :

sys-fs/e2fsprogs (the one which rdeps on the next two)
sys-libs/ss
sys-libs/com_err
app-crypt/mit-krb5-1.4 (which probably means db-4.2, but let's talk about that,
if that's not an option).

------- Comment #4 From Seemant Kulleen (RETIRED) 2005-06-21 14:35:21 0000 -------
ok, so the vulnerability is valid -- I have added 0.6.5 into portage, testing
for EVERYONE.  I will stable amd64 in about 12 hours or so -- arch teams, please
note very carefully:

The following packages need to go stable *at the same time* :

sys-fs/e2fsprogs (the one which rdeps on the next two)
sys-libs/ss
sys-libs/com_err
app-crypt/mit-krb5-1.4 (which probably means db-4.2, but let's talk about that,
if that's not an option).

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-06-21 23:19:23 0000 -------
Arches please test and mark stable not only app-crypt/heimdal but all packages  
mentioned in comment #3.  

------- Comment #6 From Michael Hanselmann (hansmi) (RETIRED) 2005-06-22 13:17:55 0000 -------
Stable on ppc.

------- Comment #7 From Gustavo Zacarias (RETIRED) 2005-06-23 11:07:10 0000 -------
I'm getting broken stuff all over the place with com_err.
For instance cvs is linked against libcom_err.so.3 and sys-libs/com_err-1.37
just provides libcom_err.so


------- Comment #8 From Sune Kloppenborg Jeppesen 2005-06-23 12:22:00 0000 -------
Back to ebuild status, unCC'ing arches. 
 
Seemant please advise. 

------- Comment #9 From Seemant Kulleen (RETIRED) 2005-06-24 06:24:42 0000 -------
revdep-rebuild after emerging libcom_err -- I will add a big fat note in the
ebuild's postinst to do so.

------- Comment #10 From Sune Kloppenborg Jeppesen 2005-06-24 07:40:07 0000 -------
Back to stable, arches please test and mark. 

------- Comment #11 From Gustavo Zacarias (RETIRED) 2005-06-24 13:31:55 0000 -------
Added einfo big fat warning to mit-krb5 too.
Fixed USE=krb4 for heimdal since it didn't build no matter the arch.
Now sparc stable.

------- Comment #12 From Seemant Kulleen (RETIRED) 2005-06-27 13:34:15 0000 -------
stable on x86 and amd64.  mips, hppa, ia64 and alpha: you guys are up!

------- Comment #13 From Michael Hanselmann (hansmi) (RETIRED) 2005-06-27 14:09:21 0000 -------
Stable on hppa.

------- Comment #14 From Bryan Østergaard (RETIRED) 2005-06-28 16:12:10 0000 -------
Alpha + ia64 stable.

------- Comment #15 From Stefan Cornelius (RETIRED) 2005-06-28 16:53:20 0000 -------
all important arches marked stable, mips promised to follow in one or two days.
glsa is already drafted and reviewed, just needs sending.

------- Comment #16 From Sune Kloppenborg Jeppesen 2005-06-29 06:13:27 0000 -------
Thx everyone. 
 
GLSA 200506-24 
 
mips please remember to mark stable to benifit from the GLSA. 

------- Comment #17 From Joshua Kinard 2005-06-29 19:29:04 0000 -------
mips stable.

First Last Prev Next    No search results available      Search page      Enter new bug