<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>135970</bug_id>
          
          <creation_ts>2006-06-07 12:22 0000</creation_ts>
          <short_desc>kde-base/arts Unchecked set*uid() calls (CVE-2006-2916)</short_desc>
          <delta_ts>2006-10-15 05:45:57 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.kde.org/info/security/advisory-20060614-2.txt</bug_file_loc>
          <status_whiteboard>A2 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kde@gentoo.org</cc>
    
    <cc>tcort@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-07 12:22:34 0000</bug_when>
            <thetext>Dirk Mueller from KDE reports:

The vixie cron vulnerability also exists in several places.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-07 12:23:50 0000</bug_when>
            <thetext>Created an attachment (id=88621)
arts-3.5.3.diff

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-07 12:27:58 0000</bug_when>
            <thetext>Carlo please attach an updated ebuild. Do not commit anything to Portage yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-09 08:10:19 0000</bug_when>
            <thetext>Nice one... Public disclosure is 2006-06-15 together with a kdm symlink attack vulnerability fix. Is there another hidden bug about it or should I open one? 

Will prepare the fixes late this evening or tomorrow.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-09 08:27:30 0000</bug_when>
            <thetext>Changing whiteboard to SEMI-PUBLIC as the general issue is already public.

Carlo up to you wether we should test the ebuild on this bug or commit direct to Portage (with only the bug number mentioned in the ChangeLog).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-11 06:35:41 0000</bug_when>
            <thetext>arts-3.4.3-r1.ebuild
arts-3.5.2-r1.ebuild


I&apos;m not sure who is responsible for KDE security bumps, but these are the ebuilds, which need to go stable. 


Sune: Sorry that I&apos;m later than predicted. Changed kde eclasses and fought with repoman acting very weird.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-06-11 06:43:19 0000</bug_when>
            <thetext>arches, please test if this is stable and report back. Altough this is set as semi-public, better dont commit anything yet. Thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2006-06-12 06:51:18 0000</bug_when>
            <thetext>Passing on to weeve, he&apos;s our kde mofo and i&apos;m not feeling quite well yet.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-12 08:21:57 0000</bug_when>
            <thetext>(In reply to comment #6)
&gt; arches, please test if this is stable and report back. Altough this is set as
&gt; semi-public, better dont commit anything yet. Thanks

Hu? I committed patch and ebuilds so everyone can read it. The patch is in KDE svn, so everyone can read it. It would be careless not to mark the ebuilds stable asap.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-12 08:25:31 0000</bug_when>
            <thetext>Please test and MARK stable, this ain&apos;t no security drill so please just mark stable in the tree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2006-06-12 11:09:54 0000</bug_when>
            <thetext>stable on ppc64

@security: remove security liasons and add archs to CC?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-12 11:35:17 0000</bug_when>
            <thetext>It&apos;s still semi public, so we cannot add arches until it is completely opened.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-06-13 19:32:40 0000</bug_when>
            <thetext>SPARC is good here (or as good as arts ever gets).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-06-14 02:13:24 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-14 06:53:10 0000</bug_when>
            <thetext>(In reply to comment #13)
&gt; ppc stable
&gt; 

You missed arts-3.4.3-r1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-06-14 08:43:36 0000</bug_when>
            <thetext>Based on comment #6, I have not touched the SPARC keywords from what they were when the ebuilds entered the tree.  Do you folks want to work this like the kdm bug or would you like the arch maestros to keyword the ebuilds?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-14 09:04:23 0000</bug_when>
            <thetext>Jason please commit, we work directly in the tree on this one (see comment #9).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-06-14 09:17:37 0000</bug_when>
            <thetext>Ah missed that one.  Thanks for the pointer :)

SPARC is now stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-06-14 11:16:15 0000</bug_when>
            <thetext>(In reply to comment #14)
&gt; (In reply to comment #13)
&gt; &gt; ppc stable
&gt; &gt; 
&gt; 
&gt; You missed arts-3.4.3-r1

Oops ;) arts-3.4.3-r1 also ppc stable :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-14 11:44:51 0000</bug_when>
            <thetext>Announcement is out, so the bug can be opened and arches cc&apos;ed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-14 12:30:55 0000</bug_when>
            <thetext>Arches please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tcort@gentoo.org</who>
            <bug_when>2006-06-15 09:17:29 0000</bug_when>
            <thetext>arts-3.4.3-r1 and arts-3.5.2-r1 stable on alpha and amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>killerfox@gentoo.org</who>
            <bug_when>2006-06-17 03:50:23 0000</bug_when>
            <thetext>stable on hppa</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-17 05:02:56 0000</bug_when>
            <thetext>Didn&apos;t want to wait forever on second pair of eyes. Stable on x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-17 06:18:14 0000</bug_when>
            <thetext>Thx Carsten.

Ready for GLSA.

Security please review draft.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-22 13:04:31 0000</bug_when>
            <thetext>GLSA 200606-22

ia64 don&apos;t forget to mark stable to benifit from the GLSA.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>88621</attachid>
            <date>2006-06-07 12:23 0000</date>
            <desc>arts-3.5.3.diff</desc>
            <filename>arts-3.5.3.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IHNvdW5kc2VydmVyL2FydHN3cmFwcGVyLmMKPT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gc291bmRzZXJ2
ZXIvYXJ0c3dyYXBwZXIuYwkocmV2aXNpb24gNTQ2OTcwKQorKysgc291bmRzZXJ2ZXIvYXJ0c3dy
YXBwZXIuYwkod29ya2luZyBjb3B5KQpAQCAtOTUsNiArOTUsMTAgQEAgaW50IG1haW4oaW50IGFy
Z2MsIGNoYXIgKiphcmd2KQogI2Vsc2UKIAkJc2V0cmV1aWQoLTEsIGdldHVpZCgpKTsKICNlbmRp
ZgorCQlpZiAoZ2V0ZXVpZCgpICE9IGdldHVpZCgpKSB7CisJCQlwZXJyb3IoInNldHVpZCgpIik7
CisJCQlyZXR1cm4gMjsKKwkJfQogCX0KIAogCWlmKGFyZ2MgPT0gMCkKSW5kZXg6IHNvdW5kc2Vy
dmVyL2NyYXNoaGFuZGxlci5jYwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBzb3VuZHNlcnZlci9jcmFzaGhhbmRs
ZXIuY2MJKHJldmlzaW9uIDU0Njk3MCkKKysrIHNvdW5kc2VydmVyL2NyYXNoaGFuZGxlci5jYwko
d29ya2luZyBjb3B5KQpAQCAtMTk2LDcgKzE5NiwxMiBAQCBDcmFzaEhhbmRsZXI6OmRlZmF1bHRD
cmFzaEhhbmRsZXIgKGludCBzCiAgICAgICAgICAgYXJndltpKytdID0gTlVMTDsKIAogICAgICAg
ICAgIHNldGdpZChnZXRnaWQoKSk7Ci0gICAgICAgICAgc2V0dWlkKGdldHVpZCgpKTsKKyAgICAg
ICAgICBpZiAoZ2V0dWlkKCkgIT0gZ2V0ZXVpZCgpKQorICAgICAgICAgICAgc2V0dWlkKGdldHVp
ZCgpKTsKKyAgICAgICAgICBpZiAoZ2V0dWlkKCkgIT0gZ2V0ZXVpZCgpKSB7CisJICAgIHBlcnJv
cigic2V0dWlkKCkiKTsKKyAgICAgICAgICAgIGV4aXQoMjU1KTsKKyAgICAgICAgICB9CiAKICAg
ICAgICAgICBleGVjdnAoY3Jhc2hBcHAsIGFyZ3YpOwogCg==
</data>        

          </attachment>
    </bug>

</bugzilla>