<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>155358</bug_id>
          
          <creation_ts>2006-11-16 07:16 0000</creation_ts>
          <short_desc>www-client/elinks arbitrary file access flaw was found in the SMB protocol handler (CVE-2006-5925)</short_desc>
          <delta_ts>2007-02-10 18:57:54 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://rhn.redhat.com/errata/RHSA-2006-0742.html</bug_file_loc>
          <status_whiteboard>B2?? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>spock@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-16 07:16:44 0000</bug_when>
            <thetext>An arbitrary file access flaw was found in the Elinks SMB protocol handler. 
A malicious web page could have caused Elinks to read or write files with 
the permissions of the user running Elinks. (CVE-2006-5925)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-11-18 11:26:04 0000</bug_when>
            <thetext>http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116355556512780&amp;w=2
http://secunia.com/advisories/22920/

upstream bug: http://bugzilla.elinks.cz/show_bug.cgi?id=841

perhaps patches could be extracted from RH update, that was for an older version though, maybe someone could check that out</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2006-11-21 04:18:05 0000</bug_when>
            <thetext>Red Hat &quot;fixed&quot; the problem by disabling smb support:

http://rhn.redhat.com/errata/RHSA-2006-0742.html

So did the guy working on the vulnerability in the elinks bugzilla.  The bug to watch for the fix is apparently:

http://bugzilla.elinks.cz/show_bug.cgi?id=844

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-01-22 19:58:44 0000</bug_when>
            <thetext>this appears to have been &quot;fixed&quot; in 0.11.2 by disabling SMB support

http://pasky.or.cz/gitweb.cgi?p=elinks.git;a=commitdiff;h=6f14725204fdd0a5f5a054ad7ab7340cd1ce27cb

Bug 841, CVE-2006-5925: Prevent enabling the SMB protocol.
src/protocol/smb/smb.c: Added #error directives so that this
vulnerable code cannot be accidentally compiled in.

features.conf: Disable CONFIG_SMB by default and explain why.

configure.in: If the user set CONFIG_SMB in features.conf or
--enable-smb in the command line, disable them and warn the user.

____

since the ebuild is in the tree already and stable on several arches, we should go on marking it stable for the others too...

www-client/elinks-0.11.2

current KEYWORDS=&quot;alpha ~amd64 ~hppa ~mips ~ppc ~ppc64 sparc ~x86 ~x86-fbsd&quot;
target KEYWORDS=&quot;alpha amd64 hppa ~mips ppc ppc64 sparc x86 ~x86-fbsd&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-01-22 21:19:08 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-01-23 03:59:49 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-01-23 09:55:10 0000</bug_when>
            <thetext>removed the samba use flag

and amd64 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-01-23 20:38:34 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-01-27 09:49:47 0000</bug_when>
            <thetext>ppc64 stable. sorry for being late</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-01-27 10:46:03 0000</bug_when>
            <thetext>we issued GLSA 200612-16, so we should have one for links too...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-10 18:57:54 0000</bug_when>
            <thetext>old GLSA 200701-27</thetext>
          </long_desc>
      
    </bug>

</bugzilla>