<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>161887</bug_id>
          
          <creation_ts>2007-01-13 12:26 0000</creation_ts>
          <short_desc>net-libs/libsoup &lt;=2.2.3, &lt;=2.2.98 missing input sanitizing Denial of Service (CVE-2006-5876)</short_desc>
          <delta_ts>2007-02-11 10:40:19 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://seclists.org/fulldisclosure/2007/Jan/0254.html</bug_file_loc>
          <status_whiteboard>B3 [noglsa] aetius</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>aetius@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>gnome@gentoo.org</cc>
    
    <cc>mips@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-01-13 12:26:08 0000</bug_when>
            <thetext>http://bugzilla.gnome.org/show_bug.cgi?id=391970
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=405197

See the gnome bug for the patch.

libsoup is missing some input sanitizing when parsing HTTP headers - in this case a binary 0 (\0x00) causes a crash.  Debian says the bug is not exploitable for anything other than a crash - initial discovery was via rhythmbox using the daap plugin.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-01-13 12:29:11 0000</bug_when>
            <thetext>setting status and cc&apos;ing herd.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>leio@gentoo.org</who>
            <bug_when>2007-01-14 07:59:51 0000</bug_when>
            <thetext>libsoup-2.2.99 is in the tree now as ~arch, which includes the fix for upstream bug 391970 as linked above.

If this bug is considered a security fix that should get quick stabilization, please CC arches yourself or let me know to do that.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-01-14 17:24:49 0000</bug_when>
            <thetext>@comment #2 - 

Do we want to stabilize a patch on any of the lower versions?  I recall something about 2.2.9x being a development branch?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>leio@gentoo.org</who>
            <bug_when>2007-01-14 17:37:55 0000</bug_when>
            <thetext>2.2.9x versions have been the minimum for GNOME since GNOME-2.14 - ftp://ftp.gnome.org/pub/GNOME/teams/releng/2.14.0/versions
We have 2.16 stable now.
So apparently upstream considers it stable. Plus many of the (stabilized) libsoup users in the tree demand at least 2.2.90.

As for SLOT=0 (1.99.28), I hope to get rid of that completely very soon, though users will have to notice to uninstall it themselves, as nothing would force an unmerge through a block.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-01-14 20:42:24 0000</bug_when>
            <thetext>Understood.  Arches, please test and mark stable:

net-libs/libsoup-2.2.99

KEYWORDS=&quot;alpha amd64 arm hppa ia64 mips ppc ppc64 ppc sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>metalgod@gentoo.org</who>
            <bug_when>2007-01-15 00:14:01 0000</bug_when>
            <thetext>amd64 stable first and the best!
thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-01-15 07:53:20 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2007-01-15 15:20:58 0000</bug_when>
            <thetext>Created an attachment (id=107068)
Test errors on Alpha

I get arather impressive amount of test errors (537212952 to be precise :) on alpha using 2.2.99. 2.2.94 passes tests with no errors. I&apos;ve attached test part of the emerge log.

Any ideas what could cause this?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-01-15 18:33:02 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2007-01-16 00:52:50 0000</bug_when>
            <thetext>SPARC is seeing the same failures when it comes to testing as Alpha is in comment #8</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-01-16 04:52:43 0000</bug_when>
            <thetext>Stable for HPPA with precisely 1076425976 test errors.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-01-16 08:56:24 0000</bug_when>
            <thetext>A negative amount failed on x86.  header-parsing is a new test introduced with .99, as the ones also available in .98 pass successfully.

-156140 errors
FAIL: header-parsing</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-01-17 07:57:34 0000</bug_when>
            <thetext>x86 stable, as the software works with libsoup...damn tests.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-01-18 18:21:06 0000</bug_when>
            <thetext>So? Should we ignore the testsuite?
How about we start using RESTRICT=&quot;test&quot; for known failures?
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-01-23 14:13:17 0000</bug_when>
            <thetext>sparc stable and disabled tests in the ebuild since they&apos;re known broken.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2007-01-23 22:11:04 0000</bug_when>
            <thetext>Stable on Alpha and IA64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-01-24 20:05:10 0000</bug_when>
            <thetext>glsa or no glsa?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-01-25 13:02:22 0000</bug_when>
            <thetext>/vote no, it&apos;s a client DoS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2007-01-26 01:05:59 0000</bug_when>
            <thetext>I vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2007-01-27 21:34:22 0000</bug_when>
            <thetext>I vote yes.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-01-27 22:48:48 0000</bug_when>
            <thetext>Another NO vote.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2007-01-28 03:31:55 0000</bug_when>
            <thetext>I don&apos;t know how I voted twice, with conflicting votes, but I really did mean to vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-10 22:26:51 0000</bug_when>
            <thetext>noglsa feel free to reopen if you disagree</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>107068</attachid>
            <date>2007-01-15 15:20 0000</date>
            <desc>Test errors on Alpha</desc>
            <filename>libsoup-2.2.99.log</filename>
            <type>text/plain</type>
            <data encoding="base64">bWFrZVszXTogTm90aGluZyB0byBiZSBkb25lIGZvciBgYWxsLWFtJy4KbWFrZVszXTogTGVhdmlu
ZyBkaXJlY3RvcnkgYC92YXIvdG1wL3BvcnRhZ2UvbGlic291cC0yLjIuOTkvd29yay9saWJzb3Vw
LTIuMi45OS9kb2NzJwptYWtlWzJdOiBMZWF2aW5nIGRpcmVjdG9yeSBgL3Zhci90bXAvcG9ydGFn
ZS9saWJzb3VwLTIuMi45OS93b3JrL2xpYnNvdXAtMi4yLjk5L2RvY3MnCm1ha2VbMl06IEVudGVy
aW5nIGRpcmVjdG9yeSBgL3Zhci90bXAvcG9ydGFnZS9saWJzb3VwLTIuMi45OS93b3JrL2xpYnNv
dXAtMi4yLjk5JwptYWtlWzJdOiBOb3RoaW5nIHRvIGJlIGRvbmUgZm9yIGBhbGwtYW0nLgptYWtl
WzJdOiBMZWF2aW5nIGRpcmVjdG9yeSBgL3Zhci90bXAvcG9ydGFnZS9saWJzb3VwLTIuMi45OS93
b3JrL2xpYnNvdXAtMi4yLjk5JwptYWtlWzFdOiBMZWF2aW5nIGRpcmVjdG9yeSBgL3Zhci90bXAv
cG9ydGFnZS9saWJzb3VwLTIuMi45OS93b3JrL2xpYnNvdXAtMi4yLjk5Jwo+Pj4gU291cmNlIGNv
bXBpbGVkLgo+Pj4gVGVzdCBwaGFzZSBbY2hlY2tdOiBuZXQtbGlicy9saWJzb3VwLTIuMi45OQpN
YWtpbmcgY2hlY2sgaW4gbGlic291cAptYWtlWzFdOiBFbnRlcmluZyBkaXJlY3RvcnkgYC92YXIv
dG1wL3BvcnRhZ2UvbGlic291cC0yLjIuOTkvd29yay9saWJzb3VwLTIuMi45OS9saWJzb3VwJwpt
YWtlICBjaGVjay1hbQptYWtlWzJdOiBFbnRlcmluZyBkaXJlY3RvcnkgYC92YXIvdG1wL3BvcnRh
Z2UvbGlic291cC0yLjIuOTkvd29yay9saWJzb3VwLTIuMi45OS9saWJzb3VwJwptYWtlWzJdOiBO
b3RoaW5nIHRvIGJlIGRvbmUgZm9yIGBjaGVjay1hbScuCm1ha2VbMl06IExlYXZpbmcgZGlyZWN0
b3J5IGAvdmFyL3RtcC9wb3J0YWdlL2xpYnNvdXAtMi4yLjk5L3dvcmsvbGlic291cC0yLjIuOTkv
bGlic291cCcKbWFrZVsxXTogTGVhdmluZyBkaXJlY3RvcnkgYC92YXIvdG1wL3BvcnRhZ2UvbGli
c291cC0yLjIuOTkvd29yay9saWJzb3VwLTIuMi45OS9saWJzb3VwJwpNYWtpbmcgY2hlY2sgaW4g
dGVzdHMKbWFrZVsxXTogRW50ZXJpbmcgZGlyZWN0b3J5IGAvdmFyL3RtcC9wb3J0YWdlL2xpYnNv
dXAtMi4yLjk5L3dvcmsvbGlic291cC0yLjIuOTkvdGVzdHMnCm1ha2UgIGNoZWNrLVRFU1RTCm1h
a2VbMl06IEVudGVyaW5nIGRpcmVjdG9yeSBgL3Zhci90bXAvcG9ydGFnZS9saWJzb3VwLTIuMi45
OS93b3JrL2xpYnNvdXAtMi4yLjk5L3Rlc3RzJwpPSwpQQVNTOiBkYXRlClJlcXVlc3QgdGVzdHMK
IDEuIEhUVFAgMS4wIHJlcXVlc3Qgd2l0aCBubyBoZWFkZXJzIChzaG91bGQgcGFyc2UpOiBPSyEK
IDIuIFJlcSB3LyAxIGhlYWRlciAoc2hvdWxkIHBhcnNlKTogT0shCiAzLiBSZXEgdy8gMSBoZWFk
ZXIsIG5vIGxlYWRpbmcgd2hpdGVzcGFjZSAoc2hvdWxkIHBhcnNlKTogT0shCiA0LiBSZXEgdy8g
MSBoZWFkZXIgaW5jbHVkaW5nIHRyYWlsaW5nIHdoaXRlc3BhY2UgKHNob3VsZCBwYXJzZSk6IE9L
IQogNS4gUmVxIHcvIDEgaGVhZGVyLCB3cmFwcGVkIChzaG91bGQgcGFyc2UpOiBPSyEKIDYuIFJl
cSB3LyAxIGhlYWRlciwgd3JhcHBlZCB3aXRoIGFkZGl0aW9uYWwgd2hpdGVzcGFjZSAoc2hvdWxk
IHBhcnNlKTogT0shCiA3LiBSZXEgdy8gMSBoZWFkZXIsIHdyYXBwZWQgd2l0aCB0YWIgKHNob3Vs
ZCBwYXJzZSk6IE9LIQogOC4gUmVxIHcvIDEgaGVhZGVyLCB3cmFwcGVkIGJlZm9yZSB2YWx1ZSAo
c2hvdWxkIHBhcnNlKTogT0shCiA5LiBSZXEgdy8gMSBoZWFkZXIgd2l0aCBlbXB0eSB2YWx1ZSAo
c2hvdWxkIHBhcnNlKTogT0shCjEwLiBSZXEgdy8gMiBoZWFkZXJzIChzaG91bGQgcGFyc2UpOiBP
SyEKMTEuIFJlcSB3LyAzIGhlYWRlcnMgKHNob3VsZCBwYXJzZSk6IE9LIQoxMi4gUmVxIHcvIDMg
aGVhZGVycywgMXN0IHdyYXBwZWQgKHNob3VsZCBwYXJzZSk6IE9LIQoxMy4gUmVxIHcvIDMgaGVh
ZGVycywgMm5kIHdyYXBwZWQgKHNob3VsZCBwYXJzZSk6IE9LIQoxNC4gUmVxIHcvIDMgaGVhZGVy
cywgM3JkIHdyYXBwZWQgKHNob3VsZCBwYXJzZSk6IE9LIQoxNS4gU3B1cmlvdXMgbGVhZGluZyBD
UkxGIChzaG91bGQgcGFyc2UpOiBPSyEKMTYuIExGIGluc3RlYWQgb2YgQ1JMRiBhZnRlciBoZWFk
ZXIgKHNob3VsZCBwYXJzZSk6IE9LIQoxNy4gTEYgaW5zdGVhZCBvZiBDUkxGIGFmdGVyIFJlcXVl
c3QtTGluZSAoc2hvdWxkIHBhcnNlKTogT0shCjE4LiBSZXEgdy8gaW5jb3JyZWN0IHdoaXRlc3Bh
Y2UgaW4gUmVxdWVzdC1MaW5lIChzaG91bGQgcGFyc2UpOiBPSyEKMTkuIEhUVFAgMC45IHJlcXVl
c3Q7IG5vdCBzdXBwb3J0ZWQgKHNob3VsZCBOT1QgcGFyc2UpOiBPSyEKMjAuIEhUVFAgMS4yIHJl
cXVlc3Q7IG5vdCBzdXBwb3J0ZWQgKG5vIHN1Y2ggdGhpbmcpIChzaG91bGQgTk9UIHBhcnNlKTog
T0shCjIxLiBOb24tSFRUUCByZXF1ZXN0IChzaG91bGQgTk9UIHBhcnNlKTogT0shCjIyLiBKdW5r
IGFmdGVyIFJlcXVlc3QtTGluZSAoc2hvdWxkIE5PVCBwYXJzZSk6IE9LIQoyMy4gTlVMIGluIE1l
dGhvZCAoc2hvdWxkIE5PVCBwYXJzZSk6IE9LIQoyNC4gTlVMIGluIFBhdGggKHNob3VsZCBOT1Qg
cGFyc2UpOiBPSyEKMjUuIE5VTCBpbiBIZWFkZXIgKHNob3VsZCBOT1QgcGFyc2UpOiBPSyEKMjYu
IEhlYWRlciBsaW5lIHdpdGggbm8gJzonIChzaG91bGQgTk9UIHBhcnNlKTogT0shCjI3LiBObyB0
ZXJtaW5hdGluZyBDUkxGIChzaG91bGQgTk9UIHBhcnNlKTogT0shCjI4LiBCbGFuayBsaW5lIGJl
Zm9yZSBoZWFkZXJzIChzaG91bGQgTk9UIHBhcnNlKTogT0shCjI5LiBCbGFuayBsaW5lIGluIGhl
YWRlcnMgKHNob3VsZCBOT1QgcGFyc2UpOiBPSyEKMzAuIEJsYW5rIGxpbmUgYWZ0ZXIgaGVhZGVy
cyAoc2hvdWxkIE5PVCBwYXJzZSk6IE9LIQoKUmVzcG9uc2UgdGVzdHMKIDEuIEhUVFAgMS4wIHJl
c3BvbnNlIHcvIG5vIGhlYWRlcnMgKHNob3VsZCBwYXJzZSk6IE9LIQogMi4gSFRUUCAxLjEgcmVz
cG9uc2Ugdy8gbm8gaGVhZGVycyAoc2hvdWxkIHBhcnNlKTogT0shCiAzLiBSZXNwb25zZSB3LyBt
dWx0aS13b3JkIFJlYXNvbi1QaHJhc2UgKHNob3VsZCBwYXJzZSk6IE9LIQogNC4gUmVzcG9uc2Ug
dy8gMSBoZWFkZXIgKHNob3VsZCBwYXJzZSk6IE9LIQogNS4gUmVzcG9uc2Ugdy8gMiBoZWFkZXJz
IChzaG91bGQgcGFyc2UpOiBPSyEKIDYuIFJlc3BvbnNlIHcvIG5vIHJlYXNvbiBwaHJhc2UgKHNo
b3VsZCBwYXJzZSk6IE9LIQogNy4gUmVzcG9uc2Ugdy8gTEYgaW5zdGVhZCBvZiBDUkxGIGFmdGVy
IFN0YXR1cy1MaW5lIChzaG91bGQgcGFyc2UpOiBPSyEKIDguIFJlc3BvbnNlIHcvIGluY29ycmVj
dCBzcGFjaW5nIGluIFN0YXR1cy1MaW5lIChzaG91bGQgcGFyc2UpOiBPSyEKIDkuIFJlc3BvbnNl
IHcvIG5vIHJlYXNvbiBwaHJhc2Ugb3IgcHJlY2VkaW5nIFNQIChzaG91bGQgcGFyc2UpOiBPSyEK
MTAuIFJlc3BvbnNlIHcvIG5vIHdoaXRlc3BhY2UgYWZ0ZXIgc3RhdHVzIGNvZGUgKHNob3VsZCBw
YXJzZSk6IE9LIQoxMS4gSW52YWxpZCBIVFRQIHZlcnNpb24gKHNob3VsZCBOT1QgcGFyc2UpOiBP
SyEKMTIuIE5vbi1IVFRQIHJlc3BvbnNlIChzaG91bGQgTk9UIHBhcnNlKTogT0shCjEzLiBOb24t
bnVtZXJpYyBzdGF0dXMgY29kZSAoc2hvdWxkIE5PVCBwYXJzZSk6IE9LIQoxNC4gTm8gc3RhdHVz
IGNvZGUgKHNob3VsZCBOT1QgcGFyc2UpOiBPSyEKMTUuIE9uZS1kaWdpdCBzdGF0dXMgY29kZSAo
c2hvdWxkIE5PVCBwYXJzZSk6IE9LIQoxNi4gVHdvLWRpZ2l0IHN0YXR1cyBjb2RlIChzaG91bGQg
Tk9UIHBhcnNlKTogT0shCjE3LiBGb3VyLWRpZ2l0IHN0YXR1cyBjb2RlIChzaG91bGQgTk9UIHBh
cnNlKTogT0shCjE4LiBTdGF0dXMgY29kZSA8IDEwMCAoc2hvdWxkIE5PVCBwYXJzZSk6IE9LIQox
OS4gU3RhdHVzIGNvZGUgPiA1OTkgKHNob3VsZCBOT1QgcGFyc2UpOiBPSyEKMjAuIE5VTCBpbiBS
ZWFzb24gUGhyYXNlIChzaG91bGQgTk9UIHBhcnNlKTogT0shCjIxLiBOVUwgaW4gSGVhZGVyIChz
aG91bGQgTk9UIHBhcnNlKTogT0shCgo1MzcyMTI5NTIgZXJyb3JzCkZBSUw6IGhlYWRlci1wYXJz
aW5nCkFic29sdXRlIFVSSSBwYXJzaW5nCjxmb286PiA9PiA8Zm9vOj4/IE9LCjxmaWxlOi9kZXYv
bnVsbD4gPT4gPGZpbGU6L2Rldi9udWxsPj8gT0sKPGZpbGU6Ly8vZGV2L251bGw+ID0+IDxmaWxl
Oi8vL2Rldi9udWxsPj8gT0sKPGZ0cDovL3VzZXJAaG9zdC9wYXRoPiA9PiA8ZnRwOi8vdXNlckBo
b3N0L3BhdGg+PyBPSwo8ZnRwOi8vdXNlckBob3N0Ojk5OTkvcGF0aD4gPT4gPGZ0cDovL3VzZXJA
aG9zdDo5OTk5L3BhdGg+PyBPSwo8ZnRwOi8vdXNlcjpwYXNzd29yZEBob3N0L3BhdGg+ID0+IDxm
dHA6Ly91c2VyQGhvc3QvcGF0aD4/IE9LCjxmdHA6Ly91c2VyOnBhc3N3b3JkQGhvc3Q6OTk5OS9w
YXRoPiA9PiA8ZnRwOi8vdXNlckBob3N0Ojk5OTkvcGF0aD4/IE9LCjxodHRwOi8vdXMlNjVyQGhv
c3Q+ID0+IDxodHRwOi8vdXNlckBob3N0Pj8gT0sKPGh0dHA6Ly91cyU0MHJAaG9zdD4gPT4gPGh0
dHA6Ly91cyU0MHJAaG9zdD4/IE9LCjxodHRwOi8vdXMlM2FyQGhvc3Q+ID0+IDxodHRwOi8vdXMl
M2FyQGhvc3Q+PyBPSwo8aHR0cDovL3VzJTJmckBob3N0PiA9PiA8aHR0cDovL3VzJTJmckBob3N0
Pj8gT0sKPGh0dHA6Ly9jb250cm9sLWNoYXJzLyUwMSUwMiUwMyUwNCUwNSUwNiUwNyUwOCUwOSUw
YSUwYiUwYyUwZCUwZSUwZiUxMCUxMSUxMiUxMyUxNCUxNSUxNiUxNyUxOCUxOSUxYSUxYiUxYyUx
ZCUxZSUxZiU3Zj4gPT4gPGh0dHA6Ly9jb250cm9sLWNoYXJzLyUwMSUwMiUwMyUwNCUwNSUwNiUw
NyUwOCUwOSUwYSUwYiUwYyUwZCUwZSUwZiUxMCUxMSUxMiUxMyUxNCUxNSUxNiUxNyUxOCUxOSUx
YSUxYiUxYyUxZCUxZSUxZiU3Zj4/IE9LCjxodHRwOi8vc3BhY2UvJTIwPiA9PiA8aHR0cDovL3Nw
YWNlLyUyMD4/IE9LCjxodHRwOi8vZGVsaW1zLyUzYyUzZSUyMyUyNSUyMj4gPT4gPGh0dHA6Ly9k
ZWxpbXMvJTNjJTNlJTIzJTI1JTIyPj8gT0sKPGh0dHA6Ly91bndpc2UtY2hhcnMvJTdiJTdkJTdj
JTVjJTVlJTViJTVkJTYwPiA9PiA8aHR0cDovL3Vud2lzZS1jaGFycy8lN2IlN2QlN2MlNWMlNWUl
NWIlNWQlNjA+PyBPSwoKUmVsYXRpdmUgVVJJIHBhcnNpbmcKPGh0dHA6Ly9hL2IvYy9kO3A/cT4g
KyA8ZzpoPiA9IDxnOmg+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDxnPiA9IDxodHRwOi8v
YS9iL2MvZz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPC4vZz4gPSA8aHR0cDovL2EvYi9j
L2c+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDxnLz4gPSA8aHR0cDovL2EvYi9jL2cvPj8g
T0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8L2c+ID0gPGh0dHA6Ly9hL2c+PyBPSwo8aHR0cDov
L2EvYi9jL2Q7cD9xPiArIDwvL2c+ID0gPGh0dHA6Ly9nPj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/
cT4gKyA8P3k+ID0gPGh0dHA6Ly9hL2IvYy8/eT4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsg
PGc/eT4gPSA8aHR0cDovL2EvYi9jL2c/eT4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPCNz
PiA9IDxodHRwOi8vYS9iL2MvZDtwP3Ejcz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPGcj
cz4gPSA8aHR0cDovL2EvYi9jL2cjcz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPGc/eSNz
PiA9IDxodHRwOi8vYS9iL2MvZz95I3M+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDw7eD4g
PSA8aHR0cDovL2EvYi9jLzt4Pj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Zzt4PiA9IDxo
dHRwOi8vYS9iL2MvZzt4Pj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Zzt4P3kjcz4gPSA8
aHR0cDovL2EvYi9jL2c7eD95I3M+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwuPiA9IDxo
dHRwOi8vYS9iL2MvPj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Li8+ID0gPGh0dHA6Ly9h
L2IvYy8+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwuLj4gPSA8aHR0cDovL2EvYi8+PyBP
Swo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwuLi8+ID0gPGh0dHA6Ly9hL2IvPj8gT0sKPGh0dHA6
Ly9hL2IvYy9kO3A/cT4gKyA8Li4vZz4gPSA8aHR0cDovL2EvYi9nPj8gT0sKPGh0dHA6Ly9hL2Iv
Yy9kO3A/cT4gKyA8Li4vLi4+ID0gPGh0dHA6Ly9hLz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+
ICsgPC4uLy4uLz4gPSA8aHR0cDovL2EvPj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Li4v
Li4vZz4gPSA8aHR0cDovL2EvZz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPD4gPSA8aHR0
cDovL2EvYi9jL2Q7cD9xPj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Li4vLi4vLi4vZz4g
PSA8aHR0cDovL2EvLi4vZz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPC4uLy4uLy4uLy4u
L2c+ID0gPGh0dHA6Ly9hLy4uLy4uL2c+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwvLi9n
PiA9IDxodHRwOi8vYS8uL2c+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwvLi4vZz4gPSA8
aHR0cDovL2EvLi4vZz4/IE9LCjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPGcuPiA9IDxodHRwOi8v
YS9iL2MvZy4+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwuZz4gPSA8aHR0cDovL2EvYi9j
Ly5nPj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Zy4uPiA9IDxodHRwOi8vYS9iL2MvZy4u
Pj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Li5nPiA9IDxodHRwOi8vYS9iL2MvLi5nPj8g
T0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Li8uLi9nPiA9IDxodHRwOi8vYS9iL2c+PyBPSwo8
aHR0cDovL2EvYi9jL2Q7cD9xPiArIDwuL2cvLj4gPSA8aHR0cDovL2EvYi9jL2cvPj8gT0sKPGh0
dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Zy8uL2g+ID0gPGh0dHA6Ly9hL2IvYy9nL2g+PyBPSwo8aHR0
cDovL2EvYi9jL2Q7cD9xPiArIDxnLy4uL2g+ID0gPGh0dHA6Ly9hL2IvYy9oPj8gT0sKPGh0dHA6
Ly9hL2IvYy9kO3A/cT4gKyA8Zzt4PTEvLi95PiA9IDxodHRwOi8vYS9iL2MvZzt4PTEveT4/IE9L
CjxodHRwOi8vYS9iL2MvZDtwP3E+ICsgPGc7eD0xLy4uL3k+ID0gPGh0dHA6Ly9hL2IvYy95Pj8g
T0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8Zz95Ly4veD4gPSA8aHR0cDovL2EvYi9jL2c/eS8u
L3g+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDxnP3kvLi4veD4gPSA8aHR0cDovL2EvYi9j
L2c/eS8uLi94Pj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8ZyNzLy4veD4gPSA8aHR0cDov
L2EvYi9jL2cjcy8uL3g+PyBPSwo8aHR0cDovL2EvYi9jL2Q7cD9xPiArIDxnI3MvLi4veD4gPSA8
aHR0cDovL2EvYi9jL2cjcy8uLi94Pj8gT0sKPGh0dHA6Ly9hL2IvYy9kO3A/cT4gKyA8aHR0cDpn
PiA9IDxFUlI+PyBPSwoKMCBlcnJvcnMKUEFTUzogdXJpLXBhcnNpbmcKPT09PT09PT09PT09PT09
PT09PQoxIG9mIDMgdGVzdHMgZmFpbGVkCj09PT09PT09PT09PT09PT09PT0KbWFrZVsyXTogKioq
IFtjaGVjay1URVNUU10gRXJyb3IgMQptYWtlWzJdOiBMZWF2aW5nIGRpcmVjdG9yeSBgL3Zhci90
bXAvcG9ydGFnZS9saWJzb3VwLTIuMi45OS93b3JrL2xpYnNvdXAtMi4yLjk5L3Rlc3RzJwptYWtl
WzFdOiAqKiogW2NoZWNrLWFtXSBFcnJvciAyCm1ha2VbMV06IExlYXZpbmcgZGlyZWN0b3J5IGAv
dmFyL3RtcC9wb3J0YWdlL2xpYnNvdXAtMi4yLjk5L3dvcmsvbGlic291cC0yLjIuOTkvdGVzdHMn
Cm1ha2U6ICoqKiBbY2hlY2stcmVjdXJzaXZlXSBFcnJvciAxCgohISEgRVJST1I6IG5ldC1saWJz
L2xpYnNvdXAtMi4yLjk5IGZhaWxlZC4KQ2FsbCBzdGFjazoKICBlYnVpbGQuc2gsIGxpbmUgMTU0
NjogICBDYWxsZWQgZHluX3Rlc3QKICBlYnVpbGQuc2gsIGxpbmUgOTg2OiAgIENhbGxlZCBzcmNf
dGVzdAogIGVidWlsZC5zaCwgbGluZSA2MTY6ICAgQ2FsbGVkIGRpZQoKISEhIE1ha2UgY2hlY2sg
ZmFpbGVkLiBTZWUgYWJvdmUgZm9yIGRldGFpbHMuCiEhISBJZiB5b3UgbmVlZCBzdXBwb3J0LCBw
b3N0IHRoZSB0b3Btb3N0IGJ1aWxkIGVycm9yLCBhbmQgdGhlIGNhbGwgc3RhY2sgaWYgcmVsZXZh
bnQuCgo=
</data>        

          </attachment>
    </bug>

</bugzilla>