<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>150748</bug_id>
          
          <creation_ts>2006-10-10 07:41 0000</creation_ts>
          <short_desc>www-servers/shttpd - buffer overflow and rce (CVE-2006-5216)</short_desc>
          <delta_ts>2006-10-30 03:12:54 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Auditing</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.milw0rm.com/exploits/2482</bug_file_loc>
          <status_whiteboard>~1 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>www-servers@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-10-10 07:41:07 0000</bug_when>
            <thetext>The POC</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-10-10 07:41:07 0000</bug_when>
            <thetext>The POC¹ is against 1.34 tested on WinXP. We have only version ~ 1.25 in the tree. I don&apos;t know, if it is affected, too. Either replacing it with 1.35 or inviting treecleaners, if no one really cares for the package should suffice.


[1] http://www.milw0rm.com/exploits/2482</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-10-11 06:44:52 0000</bug_when>
            <thetext>www-servers, any interest in keeping this? if so, pls verify/bump</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-10-19 06:09:13 0000</bug_when>
            <thetext>www-servers, pls comment</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2006-10-22 08:54:16 0000</bug_when>
            <thetext>i&apos;ve put minimal (ie. cp) effort into creating a bump ebuild, but failed...

IMHO this can be punted. www-servers/fnord is an alternative.
thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-10-23 12:44:34 0000</bug_when>
            <thetext>since this is not marked stable on any arch, pls feel free to mask-&gt;remove it</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-10-23 13:13:08 0000</bug_when>
            <thetext>i agree for masking/removing it if noone can resolve that bug.

I&apos;ll try to check if our version is really vulnerable during this week.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>stuart@gentoo.org</who>
            <bug_when>2006-10-24 00:38:02 0000</bug_when>
            <thetext>Sorry for the delay in replying.

I&apos;ve bumped this package up to 1.35.  That was released back in April, long before the exploit was posted.  I can&apos;t tell whether this version is also vulnerable or not at the moment.

Anyone in the security team fancy auditing it?

Best regards,
Stu</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-10-24 01:09:04 0000</bug_when>
            <thetext>Thanks Stuart. I&apos;ll try to have a look on this</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-10-24 05:46:45 0000</bug_when>
            <thetext>finally remove treacleaner from Cc since Stuart has taken this package :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-10-24 05:55:51 0000</bug_when>
            <thetext>The update to 1.35 should suffice. Forgot to provide the advisory url, sorry.


http://secunia.com/advisories/22294/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-10-30 03:12:54 0000</bug_when>
            <thetext>i couldn&apos;t determine if 1.25 was affected. That&apos;s not a problem since 1.35 is out after all.

I close that bug, as usual feel free to reopen if you disagree</thetext>
          </long_desc>
      
    </bug>

</bugzilla>