<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>185010</bug_id>
          
          <creation_ts>2007-07-11 22:59 0000</creation_ts>
          <short_desc>mail-client/squirrelmail G/PGP plugin code injection (CVE-2005-1924, CVE-2006-1469)</short_desc>
          <delta_ts>2007-08-11 22:06:03 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B2 [glsa] p-y</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>hanno@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>eradicator@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2007-07-11 22:59:41 0000</bug_when>
            <thetext>CVE-2005-1924
CVE-2006-4169
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=329
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=330
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=331</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2007-07-12 20:41:16 0000</bug_when>
            <thetext>I will wait two days for an updated plugin version from upstream.  If they have not addressed the issue, I&apos;ll create a patch based on the workarounds provided in the reports.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2007-07-16 01:40:21 0000</bug_when>
            <thetext>Revbumps for 1.4.10a and 1.5.1 are in portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-16 19:33:02 0000</bug_when>
            <thetext>Arches please test and mark stable. Target keywords are:

&quot;alpha amd64 ppc ppc64 sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-07-16 19:47:35 0000</bug_when>
            <thetext>mail-client/squirrelmail-1.4.10a-r2 stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-07-17 01:34:36 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-07-17 12:48:34 0000</bug_when>
            <thetext>alpha/x86 stable

amd64: please stabilize the unmasked version(1.4)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-07-17 13:19:15 0000</bug_when>
            <thetext>sparc stable yesterday, didn&apos;t i remove us from CC@ back then? (deja vu).
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cryos@gentoo.org</who>
            <bug_when>2007-07-17 21:20:57 0000</bug_when>
            <thetext>Stable on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-07-20 17:42:36 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-08-11 22:05:21 0000</bug_when>
            <thetext>it&apos;s GLSA 200708-08, thanks everybody and sorry for the delay.

</thetext>
          </long_desc>
      
    </bug>

</bugzilla>