<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>140490</bug_id>
          
          <creation_ts>2006-07-15 07:14 0000</creation_ts>
          <short_desc>sys-auth/nss_ldap - security cleanup needed</short_desc>
          <delta_ts>2006-12-01 11:38:49 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Ebuilds</component>
          <version>2006.0</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jakub@gentoo.org</reporter>
          <assigned_to>pam-bugs@gentoo.org</assigned_to>
          <cc>hansmi@gentoo.org</cc>
    
    <cc>ldap-bugs@gentoo.org</cc>
    
    <cc>robbat2@gentoo.org</cc>
    
    <cc>vorlon@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-07-15 07:14:52 0000</bug_when>
            <thetext>sys-auth/nss_ldap-174-r2: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-202: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-207: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-207-r1: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-210: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-211: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-215: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;amd64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-215-r1: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-220: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-226: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-234: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-238: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/nss_ldap-239: vulnerable via glsa(200507-13) ( ver-rev &lt; 239-r1 &amp;&amp; not ( ver = 226 &amp;&amp; ver-rev =&gt; 226-r1 ) ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)

sys-auth/pam_ldap-156: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-156: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-161: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-161: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-164: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-164: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-167: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-167: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-171: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-171: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-176: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-176: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-176-r1: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-176-r1: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-178: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-178: vulnerable via glsa(200507-13) ( ver-rev &lt; 178-r1 ), affects (&apos;alpha&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_ldap-178-r1: vulnerable via glsa(200508-22) ( ver &lt; 180 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)

sys-auth/pam_mysql-0.5: vulnerable via glsa(200606-18) ( ver &lt; 0.7_rc1 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
sys-auth/pam_mysql-0.6.0: vulnerable via glsa(200606-18) ( ver &lt; 0.7_rc1 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)

Please, clean up the above. Thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chtekk@gentoo.org</who>
            <bug_when>2006-07-15 08:34:36 0000</bug_when>
            <thetext>All vulnerable pam-mysql releases deleted.
Best regards, CHTEKK.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-09-02 16:55:59 0000</bug_when>
            <thetext>Please, do it...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2006-09-19 12:58:13 0000</bug_when>
            <thetext>&lt;hansmi&gt; robbat2: Should I clean up nss_ldap and bump to 253? (Just tested the latter one)
&lt;robbat2&gt; there are folk still reporting problems with the new ones, and they are finding a need to use the old ones still
&lt;robbat2&gt; i&apos;m certain it&apos;s upstream buggery, but I haven&apos;t managed to trace it down yet

Hence it isn&apos;t cleaned yet.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-10-11 06:19:59 0000</bug_when>
            <thetext>The older versions should really be removed if possible, since there is also another issue affecting those (s. bug #150294).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>flameeyes@gentoo.org</who>
            <bug_when>2006-10-12 09:27:16 0000</bug_when>
            <thetext>I&apos;ve removed old pam_ldap versions at least.. nss_ldap is, as Robin said, still there.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-12-01 11:38:49 0000</bug_when>
            <thetext>All done, wheeeeee! :)</thetext>
          </long_desc>
      
    </bug>

</bugzilla>