<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>159886</bug_id>
          
          <creation_ts>2007-01-03 11:47 0000</creation_ts>
          <short_desc>dev-lang/mono &lt;1.2.2.1: information disclosure with %20 (CVE-2006-6104)</short_desc>
          <delta_ts>2007-01-17 21:48:34 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B4? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>160164</dependson>
          <blocked>157288</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>compnerd@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>dotnet@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>compnerd@gentoo.org</who>
            <bug_when>2007-01-03 11:47:37 0000</bug_when>
            <thetext>This addresses a security issue (CVE-2006-6104) and is a *MUCH* improved version.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-01-06 13:43:48 0000</bug_when>
            <thetext>i am hijacking this bug for security, since this fixes a security issue

compnerd, pls assign security issues to the security team... we will handle stable marking

no need to restrict this bug either, since the issue is public and arch teams cannot access it this way</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-01-06 17:14:34 0000</bug_when>
            <thetext>In x86:

Emerges and seems to work.

However: 
Running eautoreconf in &apos;/var/tmp/portage/mono-1.2.2.1/work/mono-1.2.2.1/libgc&apos; ...
QA Notice: ${WANT_AUTOCONF} variable unset. Please report on http://bugs.gentoo.org/
QA Notice: ${WANT_AUTOMAKE} variable unset. Please report on http://bugs.gentoo.org/

Portage 2.1.1-r2 (default-linux/x86/2006.1/desktop, gcc-4.1.1, glibc-2.4-r4, 2.6.18-gentoo-r6 i686)
=================================================================
System uname: 2.6.18-gentoo-r6 i686 AMD Athlon(tm) Processor
Gentoo Base System version 1.12.6
Last Sync: Sat, 06 Jan 2007 09:50:01 +0000
distcc 2.18.3 i686-pc-linux-gnu (protocols 1 and 2) (default port 3632) [disabled]
app-admin/eselect-compiler: [Not Present]
dev-java/java-config: [Not Present]
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     [Not Present]
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS=&quot;x86&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;i686-pc-linux-gnu&quot;
CFLAGS=&quot;-march=athlon-tbird -mtune=athlon-tbird  -O2 -pipe -fomit-frame-pointer&quot;
CHOST=&quot;i686-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/gconf /etc/revdep-rebuild /etc/terminfo&quot;
CXXFLAGS=&quot;-march=athlon-tbird -mtune=athlon-tbird  -O2 -pipe -fomit-frame-pointer&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;autoconfig collision-protect distlocks metadata-transfer sandbox sfperms strict&quot;
GENTOO_MIRRORS=&quot;ftp://ftp.belnet.be/mirror/rsync.gentoo.org/gentoo/ &quot;
LC_ALL=&quot;en_US.ISO-8859-15&quot;
MAKEOPTS=&quot;-j2&quot;
PKGDIR=&quot;/tmp/lea/var/tmp/binpkgs&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --dele
te --delete-after --stats --timeout=180 --exclude=&apos;/distfiles&apos; --exclude=&apos;/local&apos; --exclude=&apos;/packages&apos;&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage /usr/portage/local/layman/sunrise&quot;
SYNC=&quot;rsync://rsync.belnet.be/packages/gentoo-portage&quot;
USE=&quot;x86 X alsa_cards_pcsp alsa_pcm_plugins_adpcm alsa_pcm_plugins_alaw alsa_pcm_plugins_asym alsa_pcm_plug
ins_copy alsa_pcm_plugins_dmix alsa_pcm_plugins_dshare alsa_pcm_plugins_dsnoop alsa_pcm_plugins_empty alsa_
pcm_plugins_extplug alsa_pcm_plugins_file alsa_pcm_plugins_hooks alsa_pcm_plugins_iec958 alsa_pcm_plugins_i
oplug alsa_pcm_plugins_ladspa alsa_pcm_plugins_lfloat alsa_pcm_plugins_linear alsa_pcm_plugins_meter alsa_p
cm_plugins_mulaw alsa_pcm_plugins_multi alsa_pcm_plugins_null alsa_pcm_plugins_plug alsa_pcm_plugins_rate a
lsa_pcm_plugins_route alsa_pcm_plugins_share alsa_pcm_plugins_shm alsa_pcm_plugins_softvol bitmap-fonts bzi
p2 cairo cdr cli cracklib crypt dbus dlloader dri dvd dvdr eds elibc_glibc emboss encode fam firefox fortra
n gif gpm gstreamer gtk hal iconv input_devices_evdev input_devices_keyboard input_devices_mouse isdnlog jp
eg kernel_linux ldap libg++ mad mikmod mp3 mpeg ncurses nptl nptlonly ogg opengl pam pcre perl png ppds ppp
d python qt3 qt4 quicktime readline reflection sdl session spell spl ssl tcpd truetype truetype-fonts type1
-fonts udev unicode userland_GNU video_cards_vesa vorbis win32codecs xml xorg xv zlib&quot;
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LDFLAGS, LINGUAS, PORTAGE_RSYNC_EXTRA_OPTS


</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-01-06 18:58:26 0000</bug_when>
            <thetext>x86 does the monkey</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-01-08 19:54:16 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mcummings@gentoo.org</who>
            <bug_when>2007-01-09 00:32:21 0000</bug_when>
            <thetext>I could not get this package to pass the test phase - is it supposed to? Looking at the portage log I see a lot of reference to /root/.config - eh? It builds and installs, but does not pass testing. Do you have any example apps I can run against it to confirm it&apos;s working? </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-01-09 08:32:01 0000</bug_when>
            <thetext>dotnet, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>compnerd@gentoo.org</who>
            <bug_when>2007-01-11 06:13:52 0000</bug_when>
            <thetext>You could try many of the various dot-net apps in portage (tomboy, muine, blam), as anything we give you would most likely be of little value.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2007-01-14 03:00:57 0000</bug_when>
            <thetext>stable on amd64.... 
the tests fail.... if its ok.. please use RESTRICT=test.... otherwise fix it ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2007-01-14 03:11:54 0000</bug_when>
            <thetext>oops</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-01-14 17:37:16 0000</bug_when>
            <thetext>Thanks everybody, everything is ok now AFAIK, now it&apos;s time to vote for a GLSA or not.

I vote for a GLSA because the exploit is trivial and can have severe consequences (disclosure of passwords, etc)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-01-14 18:42:19 0000</bug_when>
            <thetext>I vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-01-14 18:48:44 0000</bug_when>
            <thetext>padawan /vote YES</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-01-17 21:48:34 0000</bug_when>
            <thetext>GLSA 200701-12</thetext>
          </long_desc>
      
    </bug>

</bugzilla>