<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>108206</bug_id>
          
          <creation_ts>2005-10-05 11:35 0000</creation_ts>
          <short_desc>net-mail/uw-imap buffer overflow</short_desc>
          <delta_ts>2005-10-11 05:04:32 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.washington.edu/imap/</bug_file_loc>
          <status_whiteboard>B1 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-10-05 11:35:35 0000</bug_when>
            <thetext>Install imap-2004g, or later version, to fix a buffer overflow problem.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-10-05 11:37:26 0000</bug_when>
            <thetext>net-mail please bump. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-10-05 15:06:00 0000</bug_when>
            <thetext>uw-imap-2004g.ebuild is in CVS now. Note that it might not work with
FEATURES=&quot;collision-protect&quot;, as it has some common files with mail-client/pine.
Bug #105313 deals, or will deal with this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-10-05 22:26:14 0000</bug_when>
            <thetext>Arches please test and mark stable. Note comment #2. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-10-06 04:14:20 0000</bug_when>
            <thetext>uhm, wouldn&apos;t it be the best thing to block pine for 2004g and then split the
package into two parts as suggested in bug #105313 for -r1?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-10-06 04:43:14 0000</bug_when>
            <thetext>I&apos;m working on the split, and will commit -r1 in a few minutes. I suggest arch
teams wait for -r1 and test it, along with keywording the new
net-mail/uw-mailutils package.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-10-06 04:58:47 0000</bug_when>
            <thetext>Ok, net-mail/uw-mailutils-2004g and net-mail/uw-imap-2004g-r1 are now in CVS,
with the latter DEPENDing on the former.

I&apos;ve stripped KEYWORDS from the latter to just ~x86, arch teams, please keyword
uw-mailutils readd your arch back to uw-imap.

I&apos;ll do the x86 keyword, I&apos;m testing uw-imap right now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-10-06 05:22:59 0000</bug_when>
            <thetext>x86 tested and working</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-10-06 08:04:36 0000</bug_when>
            <thetext>Both done for alpha.

Cheers,
Ferdy</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-10-06 12:31:53 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2005-10-06 16:48:38 0000</bug_when>
            <thetext>Ok, tested and marked ppc64 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-10-07 03:15:40 0000</bug_when>
            <thetext>Stable on ppc and hppa. For the next time, please bump according to policy: mark
all arches unstable (~), but leave them in KEYWORDS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-10-07 04:47:28 0000</bug_when>
            <thetext>does uw-imap really hard-depend on uw-mailutils? that way it&apos;s still not
possible to have both uw-imap and pine installed, now pine just collides with
uw-mailutils, which still doesn&apos;t have DEPEND=!mail-client/pine

anyway, this is not very critical, so amd64 is stable too</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-11 05:04:32 0000</bug_when>
            <thetext>GLSA 200510-10</thetext>
          </long_desc>
      
    </bug>

</bugzilla>