<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>176226</bug_id>
          
          <creation_ts>2007-04-27 11:29 0000</creation_ts>
          <short_desc>media-gfx/gimp buffer overflow in sunras plugin (CVE-2007-2356)</short_desc>
          <delta_ts>2007-05-11 02:04:26 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/25012/</bug_file_loc>
          <status_whiteboard>A2 [glsa] p-y</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>168131</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>py@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>hanno@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-04-27 11:29:38 0000</bug_when>
            <thetext>Marsu has discovered a vulnerability in Gimp, which can be exploited by malicious people to compromise a user&apos;s system.

The vulnerability is caused due to an error within the &quot;set_color_table()&quot; function in plug-ins/common/sunras.c. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted .RAS file.

Successful exploitation may allow the execution of arbitrary code.

The vulnerability is confirmed in version 2.2.14. Other versions may also be affected.

Solution:
Do not open untrusted .RAS files.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-04-27 11:31:11 0000</bug_when>
            <thetext>setting status and cc&apos;ing maintainer.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-04-27 16:04:13 0000</bug_when>
            <thetext>No patch, no upstream information...

I&apos;ll try to get some statement from upstream asap.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-04-28 07:35:13 0000</bug_when>
            <thetext>Bumped with patch from upstream svn. Fixed in 2.2.14 and 2.3.16.

Archs please go on with stablemarking 2.2.14.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-04-28 16:03:05 0000</bug_when>
            <thetext>ia64 + x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-04-28 17:43:05 0000</bug_when>
            <thetext>mips, fyi, I&apos;ve removed the ~mips-keyword from 2.3.16, if you wanna have gimp 2.4 look that you get your dependencies ready.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-04-30 17:42:58 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-05-01 12:50:39 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-05-02 09:34:45 0000</bug_when>
            <thetext>alpha stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dang@gentoo.org</who>
            <bug_when>2007-05-02 18:53:23 0000</bug_when>
            <thetext>amd64 done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-05-03 18:42:30 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>je_fro@gentoo.org</who>
            <bug_when>2007-05-04 16:22:27 0000</bug_when>
            <thetext>gimp--2.2.14 fails with collision-detect on

* checking 1768 files for package collisions
existing file /usr/lib64/gimp/2.0/python/gimpenums.pyc is not owned by this package
existing file /usr/lib64/gimp/2.0/python/gimpfu.pyc is not owned by this package
1000 files checked ...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-05-04 17:32:20 0000</bug_when>
            <thetext>Jeffrey, collision with what? I can&apos;t think of another package owning these files, so I wonder why they are there on your system.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-05-05 12:06:13 0000</bug_when>
            <thetext>hppa cannot currently test gimp, as we need glibc-2.5 stable before gimp will work (again). Right now, gimp does not even finish loading, and hangs before it could possibly do damage through this vulnerability. When hppa&apos;s glibc-2.5 ship comes in, I will be sure to revisit gimp, test it and mark it, but as for now, gimp cannot possibly pose a threat. Please move forward without us.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-05-06 16:51:59 0000</bug_when>
            <thetext>security: I think we&apos;re ready for GLSA.

collission-issues should be fixed now, but anyway, if they still occur, please open a new bug as they&apos;ve nothing to do with this security-issue.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-05-07 21:53:20 0000</bug_when>
            <thetext>GLSA 200705-08 is out!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-05-07 21:55:24 0000</bug_when>
            <thetext>well hum, keeping opened in &quot;enhancement&quot; pending hppa/glibc resolution. Feel </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-05-07 22:09:26 0000</bug_when>
            <thetext>sorry for crashing the party, but I think the glsa is wrong.

It&apos;s not &quot;fixed in &gt;=2.2.14&quot;, but &quot;fixed in (&gt;=2.2.14 &lt;2.2.999) and &gt;=2.3.16.
It&apos;s important that ~-users update their gimp 2.3.x as well (and, of course, svn/9999-users shoudl re-merge).

Don&apos;t know if this is worth releasing an updated glsa, I leave this up to security.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-08 05:49:07 0000</bug_when>
            <thetext>2.3.x seems to be marked ~ so we don&apos;t consider that. However I do think that the GLSA lacks a warning for hppa users.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-05-08 06:13:58 0000</bug_when>
            <thetext>Hi jer or any member of HPPA team,

please could you fix the keywording stuff of gimp so that the hppa users don&apos;t remain with an apparently/possibly vulnerable version on their system:

- either mark stable 2.2.14,

- either dekeyword 2.2.*,

as you prefer, thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-05-08 14:27:09 0000</bug_when>
            <thetext>(In reply to comment #19)
&gt; Hi jer or any member of HPPA team,

Hi there!

&gt; - either mark stable 2.2.14,

Done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-05-08 20:04:49 0000</bug_when>
            <thetext>Thanks Jeroen</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2007-05-11 02:04:26 0000</bug_when>
            <thetext>mips done</thetext>
          </long_desc>
      
    </bug>

</bugzilla>