<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>187139</bug_id>
          
          <creation_ts>2007-07-30 15:10 0000</creation_ts>
          <short_desc>app-office/{koffice,kword}, kde-base/{kdegraphics,kpdf} - stack based buffer overflow (CVE-2007-3387)</short_desc>
          <delta_ts>2007-10-09 22:27:55 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>mjf@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-07-30 15:10:59 0000</bug_when>
            <thetext>kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains
a vulnerability that can cause a stack based buffer overflow
via a PDF file that exploits an integer overflow in
StreamPredictor::StreamPredictor(). We&apos;d like to thank
Derek Noonburg for bringing this issue to our attention.


Remotely supplied pdf files can be used to disrupt the kpdf
viewer on the client machine and possibly execute arbitrary code.


The upstream advisory will be out in a couple of hours. I&apos;m taking care of the patches. Is there a restricted bug for xpdf, poppler, etc. yet?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-30 15:30:15 0000</bug_when>
            <thetext>for xpdf, it&apos;s bug 185225</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-07-30 16:08:03 0000</bug_when>
            <thetext>So why weren&apos;t bugs created for the maintainers of the usual suspects of packages to be affected as well? From looking at the GLSA list aside KDE there are gpdf, libextractor, pdftohtml and possibly others to have a look at.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-07-30 18:04:50 0000</bug_when>
            <thetext>kword-1.6.3-r1 and koffice-1.6.3-r1 can go stable, kpdf-3.5.7-r1 and kdegraphics-3.5.7-r1 will be taken care of with the stabilization of KDE 3.5.7.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-08-01 13:01:54 0000</bug_when>
            <thetext>Security team, please change visibility, it&apos;s public.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-08-01 13:05:07 0000</bug_when>
            <thetext>*** Bug 187310 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-01 13:14:38 0000</bug_when>
            <thetext>thanks for the info carlo.
Arches, please test and mark stable:
kword-1.6.3-r1, target &quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86 ~x86-fbsd&quot;
koffice-1.6.3-r1, target &quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fmccor@gentoo.org</who>
            <bug_when>2007-08-01 15:00:17 0000</bug_when>
            <thetext>Sparc done for both.  koffice-1.6.3-r1 builds and installs as expected; utilities seem to work.  kword-1.6.3-r1 (same source) builds as expected and passes with FEATURES=test.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-08-01 18:16:25 0000</bug_when>
            <thetext>Marked stable for HPPA:
  app-office/koffice-1.6.3-r1
  app-office/kword-1.6.3-r1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-08-01 19:39:41 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-08-01 19:46:54 0000</bug_when>
            <thetext>alpha/ia64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-08-03 05:45:39 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-08-04 13:34:59 0000</bug_when>
            <thetext>&quot;poppler includes a copy of the xpdf code and required an update as well.&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-08-04 14:47:32 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; &quot;poppler includes a copy of the xpdf code and required an update as well.&quot;
&gt; 

Pointed that out in comment 2 already (well, didn&apos;t mention poppler being affected as it is what you&apos;d expect).


Can the security team please unrestrict bug 185225 as well!? The xpdf vuln. really isn&apos;t news anymore. Also, are there (restricted) bugs for the other packages, yet?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-08-12 14:42:45 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-09-08 22:08:44 0000</bug_when>
            <thetext>Changing status to [glsa], security please do your magic.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-10-09 22:27:55 0000</bug_when>
            <thetext>GLSA 200710-08, sorry for the delay</thetext>
          </long_desc>
      
    </bug>

</bugzilla>