<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>109997</bug_id>
          
          <creation_ts>2005-10-21 01:17 0000</creation_ts>
          <short_desc>media-libs/giflib: buffer overflow / null pointer deref</short_desc>
          <delta_ts>2005-11-20 02:14:59 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-21 01:17:32 0000</bug_when>
            <thetext>Chris Evans discovered that libungif 4.1.4 fixed potentially sensitive issues
that may be used to execute arbitrary code.

These issues were initially discovered by Daniel Eisenbud and silently fixed in
4.1.4.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-21 01:20:57 0000</bug_when>
            <thetext>Mamoru: this is a semi-public issue, could you silently add 4.1.4 to the tree so
that we are ready to disclose it by the coordinated date (2005/10/28, 1400 UTC)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-10-21 06:50:15 0000</bug_when>
            <thetext>libungif is dead

only giflib should be updated and libungif should be masked</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-21 08:49:21 0000</bug_when>
            <thetext>Release date is now set to 2005/11/03</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-28 00:37:51 0000</bug_when>
            <thetext>CVE Ids :
CVE-2005-2974 libungif NULL pointer deref
CVE-2005-3350 libungif OOB access

usata/vapier: please bump</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-10-28 16:12:56 0000</bug_when>
            <thetext>giflib-4.1.4 now in portage</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-29 02:29:55 0000</bug_when>
            <thetext>Ccing security liaisons...
Please test and mark 4.1.4 stable, so that&apos;s the ebuild is ready at GLSA release
time.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-10-29 08:55:52 0000</bug_when>
            <thetext>Stable on ppc and hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-10-29 12:53:56 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-10-30 02:53:24 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-10-31 07:21:27 0000</bug_when>
            <thetext>sparc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2005-10-31 07:45:23 0000</bug_when>
            <thetext>Marked ppc64 stable (and urt)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-03 02:53:58 0000</bug_when>
            <thetext>Adding halcyon to handle x86 stable marking.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2005-11-03 11:56:03 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-04 00:32:48 0000</bug_when>
            <thetext>Embargo ended, ready to send.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-04 00:44:26 0000</bug_when>
            <thetext>mips should mark giflib-4.1.4 ~
ppc-macos should test and mark giflib-4.1.4 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-04 00:45:05 0000</bug_when>
            <thetext>Hm. in fact mips should even test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2005-11-04 02:39:30 0000</bug_when>
            <thetext>I had to stable the follow packages to stable giflib-4.1.4:
urt-3.1b-r1
ghostscript-7.07.1-r10
media-fonts/gnu-gs-fonts-std-8.11

Note: I encountered bug #111455 but ignored it for now and stabled giflib.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-04 04:34:10 0000</bug_when>
            <thetext>GLSA 200511-03
mips should mark stable to benefit from GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2005-11-20 02:14:59 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>