<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>154334</bug_id>
          
          <creation_ts>2006-11-07 02:41 0000</creation_ts>
          <short_desc>app-arch/bsdtar: infinite loop [CVE-2006-5680]</short_desc>
          <delta_ts>2006-11-20 08:22:18 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://security.freebsd.org/advisories/FreeBSD-SA-06:24.libarchive.asc</bug_file_loc>
          <status_whiteboard>C3? [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>taviso@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>flameeyes@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2006-11-07 02:41:05 0000</bug_when>
            <thetext>infinite loop in bsdtar when handling truncated archives.

Flameeyes, please prepare an updated ebuild, but do not commit until after 8 Nov 2006 14:00 UTC.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2006-11-07 02:41:45 0000</bug_when>
            <thetext>Created an attachment (id=101383)
Patch from the FreeBSD project

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2006-11-07 02:42:21 0000</bug_when>
            <thetext>Rink Springer is credited with the discovery of this bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>flameeyes@gentoo.org</who>
            <bug_when>2006-11-07 03:00:50 0000</bug_when>
            <thetext>Created an attachment (id=101384)
bsdtar-1.3.1-r2.ebuild

Here it comes the ebuild.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>flameeyes@gentoo.org</who>
            <bug_when>2006-11-07 03:03:19 0000</bug_when>
            <thetext>(From update of attachment 101383)
Rename the patch so that it matches the ebuild&apos;s epatch line.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>flameeyes@gentoo.org</who>
            <bug_when>2006-11-07 03:06:12 0000</bug_when>
            <thetext>Also, should I update the stage we release for Gentoo/FreeBSD? Both 6.1 and 6.2, x86 and sparc, use the vulnerable bsdtar.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-07 03:13:30 0000</bug_when>
            <thetext>I don&apos;t see any need to update stages for this. Just a DoS and we don&apos;t normally rebuild for each security issue.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-11-09 06:41:20 0000</bug_when>
            <thetext>public now

flameeyes, pls commit the ebuild

from the advisory:

II.  Problem Description

If the end of an archive is reached while attempting to &quot;skip&quot; past a
region of an archive, libarchive will enter an infinite loop wherein it
repeatedly attempts (and fails) to read further data.

III. Impact

An attacker able to cause a system to extract (via &quot;tar -x&quot; or another
application which uses libarchive) or list the contents (via &quot;tar -t&quot; or
another libarchive-using application) of an archive provided by the
attacker can cause libarchive to enter an infinite loop and use all
available CPU time.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>flameeyes@gentoo.org</who>
            <bug_when>2006-11-09 06:50:19 0000</bug_when>
            <thetext>Committed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-09 08:24:51 0000</bug_when>
            <thetext>Thx Diego.

amd64 please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>thedude0001@gmx.de</who>
            <bug_when>2006-11-10 18:22:40 0000</bug_when>
            <thetext>Emerges and works fine on amd64.

Portage 2.1.1-r1 (default-linux/amd64/2006.1/desktop, gcc-4.1.1, glibc-2.4-r4, 2.6.18-suspend2-Dudebox-Edition x86_64)
=================================================================
System uname: 2.6.18-suspend2-Dudebox-Edition x86_64 AMD Athlon(tm) 64 Processor 3200+
Gentoo Base System version 1.12.6
Last Sync: Wed, 08 Nov 2006 05:00:01 +0000
distcc 2.18.3 x86_64-pc-linux-gnu (protocols 1 and 2) (default port 3632) [enabled]
ccache version 2.3 [enabled]
app-admin/eselect-compiler: [Not Present]
dev-java/java-config: 1.3.7, 2.0.30
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.3
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.60
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.13-r4
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS=&quot;amd64&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;
CFLAGS=&quot;-march=k8 -msse3 -Os -pipe&quot;
CHOST=&quot;x86_64-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config /var/qmail/control&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/terminfo&quot;
CXXFLAGS=&quot;-march=k8 -msse3 -Os -pipe&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;autoconfig ccache collision-protect distcc distlocks metadata-transfer multilib-strict parallel-fetch sandbox sfperms strict test&quot;
GENTOO_MIRRORS=&quot;ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp:///ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/&quot;
LDFLAGS=&quot;-Wl,-O1&quot;
MAKEOPTS=&quot;-j4&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=&apos;/distfiles&apos; --exclude=&apos;/local&apos; --exclude=&apos;/packages&apos;&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage_overlay&quot;
SYNC=&quot;rsync://server/gentoo-portage&quot;
USE=&quot;amd64 X alsa apache2 berkdb bitmap-fonts cairo cdr cli cracklib crypt cups dbus dlloader dri dvd dvdr eds elibc_glibc emboss encode esd fam firefox fortran gcj gdbm gif gpm gstreamer gtk gtk2 hal iconv imap input_devices_keyboard input_devices_mouse isdnlog jpeg kde kdeenablefinal kdehiddenvisibility kernel_linux libg++ mad mikmod mp3 mpeg mysql ncurses nls nptl nptlonly objc objc++ ogg oss pam pcre perl png ppds pppd python qt3 qt4 quicktime readline reflection sdl session spell spl sqlite ssl tcpd test truetype truetype-fonts type1-fonts udev unicode userland_GNU video_cards_radeon vorbis xml xorg xv zlib&quot;
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LINGUAS, PORTAGE_RSYNC_EXTRA_OPTS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2006-11-11 04:44:17 0000</bug_when>
            <thetext>mkay, stable then.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-11-11 10:21:41 0000</bug_when>
            <thetext>security, please vote on GLSA publication</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-12 09:20:29 0000</bug_when>
            <thetext>I vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-11-13 02:34:18 0000</bug_when>
            <thetext>I don&apos;t get the impact of this. Is this what is used on Gentoo/FreeBSD instead of gnu tar? Or is it just the BSD tar? If the latter I vote NO, else yes (thinking automation).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>flameeyes@gentoo.org</who>
            <bug_when>2006-11-13 05:43:49 0000</bug_when>
            <thetext>It is used by default on Gentoo/FreeBSD as default tar command, and can be used on Linux on alternative command too.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-11-13 06:20:43 0000</bug_when>
            <thetext>Thanks Diego, I was afraid you&apos;d say that .-)

So I vote YES here.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-11-20 07:49:27 0000</bug_when>
            <thetext>i vote a second no</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-20 08:22:18 0000</bug_when>
            <thetext>Two NO votes -&gt; Closing with NO GLSA. Feel free to reopen if you disagree.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>101383</attachid>
            <date>2006-11-07 02:41 0000</date>
            <desc>libarchive-1.3.1-infiniteloop.patch</desc>
            <filename>libarchive-1.3.1-infiniteloop.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IGxpYi9saWJhcmNoaXZlL2FyY2hpdmVfcmVhZF9zdXBwb3J0X2NvbXByZXNzaW9uX25v
bmUuYwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09ClJDUyBmaWxlOiAvaG9tZS9uY3ZzL3NyYy9saWIvbGliYXJjaGl2ZS9h
cmNoaXZlX3JlYWRfc3VwcG9ydF9jb21wcmVzc2lvbl9ub25lLmMsdgpyZXRyaWV2aW5nIHJldmlz
aW9uIDEuOApkaWZmIC11IC1JX19GQlNESUQgLXIxLjggYXJjaGl2ZV9yZWFkX3N1cHBvcnRfY29t
cHJlc3Npb25fbm9uZS5jCi0tLSBsaWIvbGliYXJjaGl2ZS9hcmNoaXZlX3JlYWRfc3VwcG9ydF9j
b21wcmVzc2lvbl9ub25lLmMJMjkgQXVnIDIwMDYgMDQ6NTk6MjUgLTAwMDAJMS44CisrKyBsaWIv
bGliYXJjaGl2ZS9hcmNoaXZlX3JlYWRfc3VwcG9ydF9jb21wcmVzc2lvbl9ub25lLmMJMiBOb3Yg
MjAwNiAwNToxNzoyOCAtMDAwMApAQCAtMjU3LDcgKzI1Nyw5IEBACiB9CiAKIC8qCi0gKiBTa2lw
IGF0IG1vc3QgcmVxdWVzdCBieXRlcy4gU2tpcHBlZCBkYXRhIGlzIG1hcmtlZCBhcyBjb25zdW1l
ZC4KKyAqIFNraXAgZm9yd2FyZCBieSBleGFjdGx5IHRoZSByZXF1ZXN0ZWQgYnl0ZXMgb3IgZWxz
ZSByZXR1cm4KKyAqIEFSQ0hJVkVfRkFUQUwuICBOb3RlIHRoYXQgdGhpcyBkaWZmZXJzIGZyb20g
dGhlIGNvbnRyYWN0IGZvcgorICogcmVhZF9haGVhZCwgd2hpY2ggZG9lcyBub3QgZ2F1cmFudGVl
IGEgbWluaW11bSBjb3VudC4KICAqLwogc3RhdGljIHNzaXplX3QKIGFyY2hpdmVfZGVjb21wcmVz
c29yX25vbmVfc2tpcChzdHJ1Y3QgYXJjaGl2ZSAqYSwgc2l6ZV90IHJlcXVlc3QpCkBAIC0yODcs
OSArMjg5LDcgQEAKIAlpZiAocmVxdWVzdCA9PSAwKQogCQlyZXR1cm4gKHRvdGFsX2J5dGVzX3Nr
aXBwZWQpOwogCS8qCi0JICogSWYgbm8gY2xpZW50X3NraXBwZXIgaXMgcHJvdmlkZWQsIGp1c3Qg
cmVhZCB0aGUgb2xkIHdheS4gSXQgaXMgdmVyeQotCSAqIGxpa2VseSB0aGF0IGFmdGVyIHNraXBw
aW5nLCB0aGUgcmVxdWVzdCBoYXMgbm90IHlldCBiZWVuIGZ1bGx5Ci0JICogc2F0aXNmaWVkIChh
bmQgaXMgc3RpbGwgPiAwKS4gSW4gdGhhdCBjYXNlLCByZWFkIGFzIHdlbGwuCisJICogSWYgYSBj
bGllbnRfc2tpcHBlciB3YXMgcHJvdmlkZWQsIHRyeSB0aGF0IGZpcnN0LgogCSAqLwogCWlmIChh
LT5jbGllbnRfc2tpcHBlciAhPSBOVUxMKSB7CiAJCWJ5dGVzX3NraXBwZWQgPSAoYS0+Y2xpZW50
X3NraXBwZXIpKGEsIGEtPmNsaWVudF9kYXRhLApAQCAtMzA3LDYgKzMwNywxMiBAQAogCQlhLT5y
YXdfcG9zaXRpb24gKz0gYnl0ZXNfc2tpcHBlZDsKIAkJc3RhdGUtPmNsaWVudF9hdmFpbCA9IHN0
YXRlLT5jbGllbnRfdG90YWwgPSAwOwogCX0KKwkvKgorCSAqIE5vdGUgdGhhdCBjbGllbnRfc2tp
cHBlciB3aWxsIHVzdWFsbHkgbm90IHNhdGlzZnkgdGhlCisJICogZnVsbCByZXF1ZXN0IChkdWUg
dG8gbG93LWxldmVsIGJsb2NraW5nIGNvbmNlcm5zKSwKKwkgKiBzbyBldmVuIGlmIGNsaWVudF9z
a2lwcGVyIGlzIHByb3ZpZGVkLCB3ZSBtYXkgc3RpbGwKKwkgKiBoYXZlIHRvIHVzZSBvcmRpbmFy
eSByZWFkcyB0byBmaW5pc2ggb3V0IHRoZSByZXF1ZXN0LgorCSAqLwogCXdoaWxlIChyZXF1ZXN0
ID4gMCkgewogCQljb25zdCB2b2lkKiBkdW1teV9idWZmZXI7CiAJCXNzaXplX3QgYnl0ZXNfcmVh
ZDsKQEAgLTMxNCw2ICszMjAsMTIgQEAKIAkJICAgICZkdW1teV9idWZmZXIsIHJlcXVlc3QpOwog
CQlpZiAoYnl0ZXNfcmVhZCA8IDApCiAJCQlyZXR1cm4gKGJ5dGVzX3JlYWQpOworCQlpZiAoYnl0
ZXNfcmVhZCA9PSAwKSB7CisJCQkvKiBXZSBoaXQgRU9GIGJlZm9yZSB3ZSBzYXRpc2ZpZWQgdGhl
IHNraXAgcmVxdWVzdC4gKi8KKwkJCWFyY2hpdmVfc2V0X2Vycm9yKGEsIEFSQ0hJVkVfRVJSTk9f
TUlTQywKKwkJCSAgICAiVHJ1bmNhdGVkIGlucHV0IGZpbGUgKG5lZWQgdG8gc2tpcCAlZCBieXRl
cykiLCAoaW50KXJlcXVlc3QpOworCQkJcmV0dXJuIChBUkNISVZFX0ZBVEFMKTsKKwkJfQogCQlh
c3NlcnQoYnl0ZXNfcmVhZCA+PSAwKTsgLyogcHJlY29uZGl0aW9uIGZvciBjYXN0IGJlbG93ICov
CiAJCW1pbiA9IG1pbmltdW0oKHNpemVfdClieXRlc19yZWFkLCByZXF1ZXN0KTsKIAkJYnl0ZXNf
cmVhZCA9IGFyY2hpdmVfZGVjb21wcmVzc29yX25vbmVfcmVhZF9jb25zdW1lKGEsIG1pbik7Cg==
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>101384</attachid>
            <date>2006-11-07 03:00 0000</date>
            <desc>bsdtar-1.3.1-r2.ebuild</desc>
            <filename>bsdtar-1.3.1-r2.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA2IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6IC92YXIvY3Zzcm9vdC9nZW50b28teDg2L2FwcC1hcmNoL2JzZHRhci9ic2R0YXItMS4zLjEt
cjEuZWJ1aWxkLHYgMS4zIDIwMDYvMTAvMTcgMTI6MDE6MTAgdWJlcmxvcmQgRXhwICQKCldBTlRf
QVVUT0NPTkY9bGF0ZXN0CldBTlRfQVVUT01BS0U9bGF0ZXN0Cgppbmhlcml0IGV1dGlscyBhdXRv
dG9vbHMgdG9vbGNoYWluLWZ1bmNzIGZsYWctby1tYXRpYwoKTVlfUD0ibGliYXJjaGl2ZS0ke1BW
fSIKCkRFU0NSSVBUSU9OPSJCU0QgdGFyIGNvbW1hbmQiCkhPTUVQQUdFPSJodHRwOi8vcGVvcGxl
LmZyZWVic2Qub3JnL35raWVudHpsZS9saWJhcmNoaXZlLyIKU1JDX1VSST0iaHR0cDovL3Blb3Bs
ZS5mcmVlYnNkLm9yZy9+a2llbnR6bGUvbGliYXJjaGl2ZS9zcmMvJHtNWV9QfS50YXIuZ3oiCgpM
SUNFTlNFPSJCU0QiClNMT1Q9IjAiCktFWVdPUkRTPSJ+YW1kNjQgfmhwcGEgfnBwYyB+c3BhcmMt
ZmJzZCB+eDg2IH54ODYtZmJzZCIKSVVTRT0iYnVpbGQgc3RhdGljIGFjbCB4YXR0ciIKClJERVBF
TkQ9IiFkZXYtbGlicy9saWJhcmNoaXZlCglrZXJuZWxfbGludXg/ICgKCQlhY2w/ICggc3lzLWFw
cHMvYWNsICkKCQl4YXR0cj8gKCBzeXMtYXBwcy9hdHRyICkKCSkKCSFzdGF0aWM/ICggIWJ1aWxk
PyAoCgkJYXBwLWFyY2gvYnppcDIKCQlzeXMtbGlicy96bGliICkgKSIKREVQRU5EPSIke1JERVBF
TkR9CglrZXJuZWxfbGludXg/ICggc3lzLWZzL2UyZnNwcm9ncwoJCXZpcnR1YWwvb3MtaGVhZGVy
cyApIgoKUz0iJHtXT1JLRElSfS8ke01ZX1B9IgoKc3JjX3VucGFjaygpIHsKCXVucGFjayAke0F9
CgljZCAiJHtTfSIKCgllcGF0Y2ggIiR7RklMRVNESVJ9Ii9saWJhcmNoaXZlLTEuMy4xLXN0YXRp
Yy5wYXRjaAoJZXBhdGNoICIke0ZJTEVTRElSfSIvbGliYXJjaGl2ZS0xLjIuNTctYWNsLnBhdGNo
CgllcGF0Y2ggIiR7RklMRVNESVJ9Ii9saWJhcmNoaXZlLTEuMi41My1zdHJpY3QtYWxpYXNpbmcu
cGF0Y2gKCWVwYXRjaCAiJHtGSUxFU0RJUn0iL2xpYmFyY2hpdmUtMS4zLjEtaW5maW5pdGVsb29w
LnBhdGNoCgoJZWF1dG9yZWNvbmYKCWVwdW50X2N4eAp9CgpzcmNfY29tcGlsZSgpIHsKCWxvY2Fs
IG15Y29uZgoKCWlmIHVzZSBzdGF0aWMgfHwgdXNlIGJ1aWxkIDsgdGhlbgoJCW15Y29uZj0iJHtt
eWNvbmZ9IC0tZW5hYmxlLXN0YXRpYy1ic2R0YXIiCgllbHNlCgkJbXljb25mPSIke215Y29uZn0g
LS1kaXNhYmxlLXN0YXRpYy1ic2R0YXIiCglmaQoKCWVjb25mIFwKCQktLWJpbmRpcj0vYmluIFwK
CQkkKHVzZV9lbmFibGUgYWNsKSBcCgkJJCh1c2VfZW5hYmxlIHhhdHRyKSBcCgkJJHtteWNvbmZ9
IHx8IGRpZSAiZWNvbmYgZmFpbGVkIgoJZW1ha2UgfHwgZGllICJlbWFrZSBmYWlsZWQiCn0KCnNy
Y19pbnN0YWxsKCkgewoJZW1ha2UgLWoxIERFU1RESVI9IiR7RH0iIGluc3RhbGwgfHwgZGllICJl
bWFrZSBpbnN0YWxsIGZhaWxlZCIKCgkjIENyZWF0ZSB0YXIgc3ltbGluayBmb3IgRnJlZUJTRAoJ
aWYgW1sgJHtDSE9TVH0gPT0gKi1mcmVlYnNkKiBdXTsgdGhlbgoJCWRvc3ltIGJzZHRhciAvYmlu
L3RhcgoJCWRvc3ltIGJzZHRhci4xLmd6IC91c3Ivc2hhcmUvbWFuL21hbjEvdGFyLjEuZ3oKCWZp
CgoJaWYgdXNlIGJ1aWxkOyB0aGVuCgkJcm0gLXJmICIke0R9Ii91c3IKCQlybSAtcmYgIiR7RH0i
L2xpYi8qLnNvKgoJCXJldHVybiAwCglmaQoKCWRvZGlyIC8kKGdldF9saWJkaXIpCgltdiAiJHtE
fSIvdXNyLyQoZ2V0X2xpYmRpcikvKi5zbyogIiR7RH0iLyQoZ2V0X2xpYmRpcikKCWdlbl91c3Jf
bGRzY3JpcHQgbGliYXJjaGl2ZS5zbwp9Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>