<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>178851</bug_id>
          
          <creation_ts>2007-05-17 09:42 0000</creation_ts>
          <short_desc>dev-java/{sun-jdk|sun-jre-bin} 1.6.0* image parsing library vulnerabilities (ICC parsing, BMP parsing) (CVE-2007-2788, CVE-2007-2789)</short_desc>
          <delta_ts>2008-04-17 23:43:35 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://scary.beasts.org/security/CESA-2006-004.html</bug_file_loc>
          <status_whiteboard>B2? [glsa+] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>172854</dependson>
          <blocked>177842</blocked>
    
    <blocked>215614</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>caster@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>java@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-05-17 09:42:13 0000</bug_when>
            <thetext>Originally reported by Martin Capitanio &lt;gentoo-bug@capitanio.org&gt; in bug 178575.

Programs affected: JDK 1.5.0_07-b03 and others.
Fixed in: JDK 1.5.0_11-b03 and JDK 1.6.0_01-b06.
Severity: Probable remote compromise of systems which use the vulnerable JDK APIs to parse images.

We already have 1.5.0.11 stabled so that&apos;s fine but we need to finally get them to release 1.6.0_01 under DLJ.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-18 06:41:23 0000</bug_when>
            <thetext>Handling app-emulation/emul-linux-x86-java on bug 178962.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-19 22:29:10 0000</bug_when>
            <thetext>*** Bug 179155 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-05-20 20:30:13 0000</bug_when>
            <thetext>To sum it up, for 1.6 this is probably [upstream] because they didn&apos;t release fixed version under the friendly license yet.
For 1.5 you could glsa it together with 176675 (if that&apos;s possible per your policies?) because the fixed version is the same - 1.5.0.11. But this bug isn&apos;t applicable for 1.4 which is also handled by 176675 so dunno.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-21 03:52:06 0000</bug_when>
            <thetext>Thx Caster. I think we&apos;re going to combine them. Also as long as 1.6.x is not stable we (security) don&apos;t mind.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-06-01 07:14:45 0000</bug_when>
            <thetext>200705-23 combined with bug 176675</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-06-01 07:41:48 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; Thx Caster. I think we&apos;re going to combine them. Also as long as 1.6.x is not
&gt; stable we (security) don&apos;t mind.

But x86 already stabilized 1.6.0 jre</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2007-06-02 16:33:41 0000</bug_when>
            <thetext>(In reply to comment #6)
&gt; (In reply to comment #4)
&gt; &gt; Thx Caster. I think we&apos;re going to combine them. Also as long as 1.6.x is not
&gt; &gt; stable we (security) don&apos;t mind.
&gt; 
&gt; But x86 already stabilized 1.6.0 jre
&gt; 

u1 is out. x86 please mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-06-03 22:44:45 0000</bug_when>
            <thetext>&gt; u1 is out. x86 please mark stable

Precisely, dev-java/sun-jre-bin-1.6.0.01-r1 

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-06-04 07:48:54 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2007-06-04 21:12:18 0000</bug_when>
            <thetext>(In reply to comment #9)
&gt; x86 stable
&gt; 

Or not.
  04 Jun 2007; Christian Faulhammer &lt;opfer@gentoo.org&gt; ChangeLog:
  stable x86, security bug 178851
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-06-05 05:11:46 0000</bug_when>
            <thetext>I stabled the wrong version, sorry for that.  x86 done again</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-06-10 18:16:59 0000</bug_when>
            <thetext>it was 200705-23 combined with bug 176675</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-06-10 18:31:49 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; it was 200705-23 combined with bug 176675

But that wasn&apos;t dealing with 1.6 JDK, because we didn&apos;t have fixed version available that time.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-06-11 06:41:11 0000</bug_when>
            <thetext>Caster are we still waiting for upstream on 1.6?

We&apos;ll close this one once we have an unstable ebuild for 1.6.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-06-11 08:59:56 0000</bug_when>
            <thetext>(In reply to comment #14)
&gt; Caster are we still waiting for upstream on 1.6?

No.

&gt; We&apos;ll close this one once we have an unstable ebuild for 1.6.

You might want to do glsa because vulnerable version was stable on x86 (and now the fixed one is stable, see comment 11)

Vulnerable that was stable: dev-java/sun-jre-bin-1.6.0-r1
Fixed that is stable: dev-java/sun-jre-bin-1.6.0.01-r1


</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-06-16 06:56:01 0000</bug_when>
            <thetext>Security please comment on GLSA need.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-06-20 08:25:39 0000</bug_when>
            <thetext>we released glsa 200705-23 for a similar issue, so I guess we should have another one for this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-01 02:17:52 0000</bug_when>
            <thetext>Security please vote.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-07-02 21:25:01 0000</bug_when>
            <thetext>I vote yes, we glsa&apos;d the JPEG/BMP one, this is basically the same thing.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-07-02 21:32:24 0000</bug_when>
            <thetext>You can do the GLSA together with bug 183580 which is same package different slot (maybe I didn&apos;t have to open extra bug for it anyways...)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 07:24:02 0000</bug_when>
            <thetext>Voting YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-09-11 11:21:35 0000</bug_when>
            <thetext>changing product/component

please file security bugs in the Gentoo Security product</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-31 19:05:43 0000</bug_when>
            <thetext>I would close this bug without a GLSA because the GLSA has been updated more than half a year ago:

----------------------------
revision 1.2
date: 2007-06-05 16:24:43 +0200;  author: falco;  state: Exp;  lines: +4 -3;  commitid: 72f7466571f24567;
add the 1.6.x branch of sun-jre-bin since it had been stabilized on x86 just a few days before the glsa was sent.
----------------------------

--- glsa-200705-23.xml  31 May 2007 18:12:05 -0000      1.1
+++ glsa-200705-23.xml  5 Jun 2007 14:24:43 -0000       1.2
@@ -11,7 +11,7 @@
   &lt;/synopsis&gt;
   &lt;product type=&quot;ebuild&quot;&gt;sun-jdk,sun-jre-bin&lt;/product&gt;
   &lt;announced&gt;May 31, 2007&lt;/announced&gt;
-  &lt;revised&gt;May 31, 2007: 01&lt;/revised&gt;
+  &lt;revised&gt;June 05, 2007: 02&lt;/revised&gt;
   &lt;bug&gt;176675&lt;/bug&gt;
   &lt;bug&gt;178851&lt;/bug&gt;
   &lt;access&gt;remote&lt;/access&gt;
@@ -22,9 +22,10 @@
       &lt;vulnerable range=&quot;lt&quot;&gt;1.5.0.11&lt;/vulnerable&gt;
     &lt;/package&gt;
     &lt;package name=&quot;dev-java/sun-jre-bin&quot; auto=&quot;yes&quot; arch=&quot;*&quot;&gt;
-      &lt;unaffected range=&quot;ge&quot;&gt;1.5.0.11&lt;/unaffected&gt;
+      &lt;unaffected range=&quot;rge&quot;&gt;1.5.0.11&lt;/unaffected&gt;
       &lt;unaffected range=&quot;rge&quot;&gt;1.4.2.14&lt;/unaffected&gt;
-      &lt;vulnerable range=&quot;lt&quot;&gt;1.5.0.11&lt;/vulnerable&gt;
+      &lt;unaffected range=&quot;ge&quot;&gt;1.6.0.01&lt;/unaffected&gt;
+      &lt;vulnerable range=&quot;lt&quot;&gt;1.6.0.01&lt;/vulnerable&gt;
     &lt;/package&gt;
   &lt;/affected&gt;
   &lt;background&gt;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-31 19:09:34 0000</bug_when>
            <thetext>Oh wait, that did not deal with the JDK. Assuming that was affected, it needs to get GLSA&apos;d.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-17 23:43:35 0000</bug_when>
            <thetext>GLSA 200804-20, sorry for the long delay.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>