<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>112213</bug_id>
          <alias>CVE-2005-2929</alias>
          <creation_ts>2005-11-11 11:48 0000</creation_ts>
          <short_desc>www-client/lynx: arbitrary command execution via lynxcgi (CVE-2005-2929)</short_desc>
          <delta_ts>2008-10-21 14:25:52 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113172754719215&amp;w=2</bug_file_loc>
          <status_whiteboard>A2 [stable]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>taviso@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>dmwaters@gentoo.org</cc>
    
    <cc>seemant@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-11 11:48:42 0000</bug_when>
            <thetext>dmwaters, please bump to 2.8.6dev.15 asap.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2005-11-11 22:09:30 0000</bug_when>
            <thetext>Created an attachment (id=72720)
lynx-2.8.6_pre15.ebuild

Here are the changes I had to make in my local tree for this bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2005-11-12 12:44:50 0000</bug_when>
            <thetext>adding ppc-macos to check the patch.  ppc-macos keyword is dropped in the patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2005-11-12 13:51:04 0000</bug_when>
            <thetext>Created an attachment (id=72774)
ppc-macos changes

applying the above patch to the lynx-2.8.6_pre15.ebuild file, cleans up the
darwin/osx mess.  This new version seems to compile and work fine for ppc-macos
without additional tweaks.   I tested, and hence added back the ~ppc-macos
keyword.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2005-11-12 17:46:26 0000</bug_when>
            <thetext>arch teams -- please test lynx-2.8.5-r2 and mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2005-11-12 17:47:10 0000</bug_when>
            <thetext>Fabian -- please make sure ppc-macos is ok with 2.8.5-r2 as well</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2005-11-12 18:23:29 0000</bug_when>
            <thetext>silly seemant you asked for arch testing but forgot to ~arch the keywords. 
I reverted those for you and the arches right quick. I also tested on x86 and it 
looks pretty good so I left it in stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2005-11-12 18:45:35 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2005-11-12 18:49:24 0000</bug_when>
            <thetext>Stable on SPARC</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hparker@gentoo.org</who>
            <bug_when>2005-11-12 19:13:30 0000</bug_when>
            <thetext>amd64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2005-11-13 02:26:14 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; Fabian -- please make sure ppc-macos is ok with 2.8.5-r2 as well

At your service!

marked 2.8.5-r2 stable and made darwin patch unconditional (getting rid of the
conditional in the ebuild)

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-11-13 03:47:40 0000</bug_when>
            <thetext>Alpha happy</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-11-13 03:55:21 0000</bug_when>
            <thetext>Stable on ppc, hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-13 09:24:15 0000</bug_when>
            <thetext>GLSA 200511-09
arm, ia64, mips, s390 should mark stable to benefit from GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2005-11-15 11:40:45 0000</bug_when>
            <thetext>ia64 and mips, please do mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2005-11-20 01:42:18 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>72720</attachid>
            <date>2005-11-11 22:09 0000</date>
            <desc>lynx-2.8.6_pre15.ebuild</desc>
            <filename>lynx-2.8.6_pre15.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA1IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6IC92YXIvY3Zzcm9vdC9nZW50b28teDg2L3d3dy1jbGllbnQvbHlueC9seW54LTIuOC41LXIx
LmVidWlsZCx2IDEuMSAyMDA1LzEwLzE3IDExOjU4OjM3IHNlZW1hbnQgRXhwICQKCmluaGVyaXQg
ZXV0aWxzIGZsYWctby1tYXRpYwoKU0VDX1Y9MjAwNS0zMTIwCgpNWV9QPSR7UC8tL30KREVTQ1JJ
UFRJT049IkFuIGV4Y2VsbGVudCBjb25zb2xlLWJhc2VkIHdlYiBicm93c2VyIHdpdGggc3NsIHN1
cHBvcnQiCkhPTUVQQUdFPSJodHRwOi8vbHlueC5icm93c2VyLm9yZy8iClM9JHtXT1JLRElSfS8k
e1BOfSR7UFYvLy4vLX0KCmlmIFtbICIke01ZX1AvX3ByZS99IiA9PSAiJHtNWV9QfSIgXV07IHRo
ZW4KCVNSQ19VUkk9ImZ0cDovL2x5bnguaXNjLm9yZy8ke01ZX1B9LyR7TVlfUH0udGFyLmJ6MiIK
ZWxzZQoJU1JDX1VSST0iZnRwOi8vbHlueC5pc2Mub3JnL2N1cnJlbnQvJHtNWV9QL19wcmUvZGV2
Ln0udGFyLmJ6MiIKCU1ZX1BWPSR7UFYvLy4vLX0KCVM9JHtXT1JLRElSfS8ke1BOfSR7TVlfUFY6
MDo1fQpmaQoKTElDRU5TRT0iR1BMLTIiClNMT1Q9IjAiCktFWVdPUkRTPSJ+YWxwaGEgfmFtZDY0
IH5hcm0gfmhwcGEgfmlhNjQgfm1pcHMgfnBwYyB+cHBjNjQgfnMzOTAgfnNwYXJjIH54ODYiCiMg
cHBjLW1hY29zIGRyb3BwZWQuLiBuZWVkcyBwYXRjaCBsb3ZpbmcKSVVTRT0ic3NsIG5scyBpcHY2
IgoKREVQRU5EPSJzeXMtbGlicy9uY3Vyc2VzCglzeXMtbGlicy96bGliCglubHM/ICggc3lzLWRl
dmVsL2dldHRleHQgKQoJc3NsPyAoID49ZGV2LWxpYnMvb3BlbnNzbC0wLjkuNiApIgpQUk9WSURF
PSJ2aXJ0dWFsL3RleHRicm93c2VyIgoKc3JjX3VucGFjaygpIHsKCXVucGFjayAke0F9OyBjZCAk
e1N9IHx8IGRpZSAiY2hkaXIgJFMiCiMJZXBhdGNoICR7V09SS0RJUn0vJHtQfS1DQU4tJHtTRUNf
Vn0ucGF0Y2gKIwl1c2UgdXNlcmxhbmRfRGFyd2luICYmIGVwYXRjaCAke0ZJTEVTRElSfS8ke1B9
LWRhcndpbi5wYXRjaAp9CgpzcmNfY29tcGlsZSgpIHsKCWxvY2FsIG15Y29uZgoJdXNlIHNzbCAm
JiBteWNvbmY9IiR7bXljb25mfSAtLXdpdGgtc3NsPXllcyIKCglhcHBlbmQtZmxhZ3MgLURBTlNJ
X1ZBUkFSR1MKCgllY29uZiBcCgkJLS1saWJkaXI9L2V0Yy9seW54IFwKCQktLWVuYWJsZS1jZ2kt
bGlua3MgXAoJCS0tZW5hYmxlLUVYUF9QRVJTSVNURU5UX0NPT0tJRVMgXAoJCS0tZW5hYmxlLXBy
ZXR0eXNyYyBcCgkJLS1lbmFibGUtbnNsLWZvcmsgXAoJCS0tZW5hYmxlLWZpbGUtdXBsb2FkIFwK
CQktLWVuYWJsZS1yZWFkLWV0YSBcCgkJLS1lbmFibGUtbGlianMgXAoJCS0tZW5hYmxlLWNvbG9y
LXN0eWxlIFwKCQktLWVuYWJsZS1zY3JvbGxiYXIgXAoJCS0tZW5hYmxlLWluY2x1ZGVkLW1zZ3Mg
XAoJCS0td2l0aC16bGliIFwKCQkkKHVzZV9lbmFibGUgbmxzKSBcCgkJJCh1c2VfZW5hYmxlIGlw
djYpIFwKCQkke215Y29uZn0gfHwgZGllCgoJZW1ha2UgfHwgZGllICJjb21waWxlIHByb2JsZW0i
Cn0KCnNyY19pbnN0YWxsKCkgewoJZWluc3RhbGwgbGliZGlyPSR7RH0vZXRjL2x5bnggfHwgZGll
CgoJZG9zZWQgInN8XkhFTFBGSUxFLiokfEhFTFBGSUxFOmZpbGU6Ly9sb2NhbGhvc3QvdXNyL3No
YXJlL2RvYy8ke1BGfS9seW54X2hlbHAvbHlueF9oZWxwL2x5bnhfaGVscF9tYWluLmh0bWx8IiBc
CgkJCS9ldGMvbHlueC9seW54LmNmZwoJZG9kb2MgQ0hBTkdFUyBDT1BZSEVBREVSIElOU1RBTExB
VElPTiBQUk9CTEVNUyBSRUFETUUKCWRvY2ludG8gZG9jcwoJZG9kb2MgZG9jcy8qCglkb2NpbnRv
IGx5bnhfaGVscAoJZG9kb2MgbHlueF9oZWxwLyoudHh0Cglkb2h0bWwgLXIgbHlueF9oZWxwCgoJ
IyBzbWFsbCBsaXR0bGUgbWFucGFnZSBnbGl0Y2gKCXJtICR7RH0vdXNyL3NoYXJlL21hbi9seW54
LjEKCW5ld21hbiBseW54Lm1hbiBseW54LjEKfQo=
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>72774</attachid>
            <date>2005-11-12 13:51 0000</date>
            <desc>ppc-macos changes</desc>
            <filename>patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGF0dGFjaG1lbnQuY2dpP2lkPTcyNzIwCTIwMDUtMTEtMTIgMjI6NDg6MjEuMDAwMDAwMDAw
ICswMTAwCisrKyBseW54LTIuOC42X3ByZTE1LmVidWlsZAkyMDA1LTExLTEyIDIyOjQ4OjQ5LjAw
MDAwMDAwMCArMDEwMApAQCAtMjEsOCArMjEsNyBAQAogCiBMSUNFTlNFPSJHUEwtMiIKIFNMT1Q9
IjAiCi1LRVlXT1JEUz0ifmFscGhhIH5hbWQ2NCB+YXJtIH5ocHBhIH5pYTY0IH5taXBzIH5wcGMg
fnBwYzY0IH5zMzkwIH5zcGFyYyB+eDg2IgotIyBwcGMtbWFjb3MgZHJvcHBlZC4uIG5lZWRzIHBh
dGNoIGxvdmluZworS0VZV09SRFM9In5hbHBoYSB+YW1kNjQgfmFybSB+aHBwYSB+aWE2NCB+bWlw
cyB+cHBjIH5wcGMtbWFjb3MgfnBwYzY0IH5zMzkwIH5zcGFyYyB+eDg2IgogSVVTRT0ic3NsIG5s
cyBpcHY2IgogCiBERVBFTkQ9InN5cy1saWJzL25jdXJzZXMKQEAgLTM0LDcgKzMzLDYgQEAKIHNy
Y191bnBhY2soKSB7CiAJdW5wYWNrICR7QX07IGNkICR7U30gfHwgZGllICJjaGRpciAkUyIKICMJ
ZXBhdGNoICR7V09SS0RJUn0vJHtQfS1DQU4tJHtTRUNfVn0ucGF0Y2gKLSMJdXNlIHVzZXJsYW5k
X0RhcndpbiAmJiBlcGF0Y2ggJHtGSUxFU0RJUn0vJHtQfS1kYXJ3aW4ucGF0Y2gKIH0KIAogc3Jj
X2NvbXBpbGUoKSB7Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>