<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>193095</bug_id>
          
          <creation_ts>2007-09-19 17:13 0000</creation_ts>
          <short_desc>net-libs/opal &lt;2.2.11 dev-libs/pwlib: Two DoS vulnerabilitues in Ekiga (CVE-2007-{4897,4924})</short_desc>
          <delta_ts>2007-10-17 22:16:46 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://mail.gnome.org/archives/ekiga-list/2007-September/msg00103.html</bug_file_loc>
          <status_whiteboard>B3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>cycloon@is-root.org</cc>
    
    <cc>gentoo-bug@capitanio.org</cc>
    
    <cc>voip@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-19 17:13:26 0000</bug_when>
            <thetext>From RedHat:
  José Miguel Esparza discovered that insufficient input validation is
  performed on SIP protocol header field &apos;Content-Length&apos; by opal library
  used by ekiga. This flaw can be used to write &apos;\0&apos; byte to
  attacker-controlled address and crash ekiga.  Ekiga 2.0.10 using opal
  library 2.2.10 was released to address this issue.

I am not aware whether the versions in our tree are affected, the patch linked
to at the RedHat bug references a code that is not in in opal-2.2.8.
( https://bugzilla.redhat.com/296371 )</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-19 17:14:52 0000</bug_when>
            <thetext>Whiteboard and cc&apos;ing maintainers.

voip, please advise and patch as necessary.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-24 22:10:32 0000</bug_when>
            <thetext>voip, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-10-01 19:37:50 0000</bug_when>
            <thetext>*** Bug 194434 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-02 08:02:25 0000</bug_when>
            <thetext>voip, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-10-08 08:08:08 0000</bug_when>
            <thetext>*** Bug 195068 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo-bug@capitanio.org</who>
            <bug_when>2007-10-08 08:47:15 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; *** Bug 195068 has been marked as a duplicate of this bug. ***
&gt; 
that is not &quot;a duplicate of this bug&quot;, but actually a small patch
and ebuild bump for ekiga-2.0.11

(Jakube, as http://bugs.gentoo.org/buglist.cgi?quicksearch=%23ekiga
does&apos;t list it, nobody can probably find it.)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-10-08 15:36:45 0000</bug_when>
            <thetext>2.0.11 for both are in the tree</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-08 22:08:53 0000</bug_when>
            <thetext>Created an attachment (id=132965)
pwlib-1.10.1-vsprintf.patch

RedHat issued a pwlib advisory for CVE-2007-4897. The CVE info states that Ekiga after 2.0.5 is not affected, which is false according to their bug. https://bugzilla.redhat.com/292831

I&apos;ll attach the patch that was also applied to pwlib upstream, we should include this. Sorry I didn&apos;t notice earlier.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-09 21:17:57 0000</bug_when>
            <thetext>updated pwlib is in the tree now.

Arches, please test and mark stable:
* dev-libs/pwlib-1.10.10-r1
* net-libs/opal-2.2.6
* net-im/ekiga-2.0.11

Targets are: &quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86&quot;

Please also test that the new pwlib also works with its other rrdeps.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-10-10 05:57:53 0000</bug_when>
            <thetext>(In reply to comment #9)
&gt; Arches, please test and mark stable:
&gt; * net-libs/opal-2.2.6

 I think you mean opal 2.2.11?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-10-10 08:11:44 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-10 08:39:17 0000</bug_when>
            <thetext>(In reply to comment #10)
&gt; (In reply to comment #9)
&gt; &gt; Arches, please test and mark stable:
&gt; &gt; * net-libs/opal-2.2.6
&gt; 
&gt;  I think you mean opal 2.2.11?

Yes, my bad.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-10-10 16:55:57 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kingtaco@gentoo.org</who>
            <bug_when>2007-10-11 07:07:28 0000</bug_when>
            <thetext>* dev-libs/pwlib-1.10.10-r1
* net-libs/opal-2.2.6
* net-im/ekiga-2.0.11

amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-11 09:37:47 0000</bug_when>
            <thetext>(In reply to comment #14)
&gt; * dev-libs/pwlib-1.10.10-r1
&gt; * net-libs/opal-2.2.6
&gt; * net-im/ekiga-2.0.11
&gt; 
&gt; amd64 stable

net-libs/opal-2.2.11 please. That was a typo up there.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-10-11 09:44:19 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-10-11 18:40:48 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-11 20:23:11 0000</bug_when>
            <thetext>amd64 done here.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-10-12 16:03:29 0000</bug_when>
            <thetext>ppc stable, ready for glsa-voting</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-10-17 18:36:14 0000</bug_when>
            <thetext>I vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-10-17 22:16:46 0000</bug_when>
            <thetext>voting no too, and closing.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>132965</attachid>
            <date>2007-10-08 22:08 0000</date>
            <desc>pwlib-1.10.1-vsprintf.patch</desc>
            <filename>pwlib-1.10.1-vsprintf.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIHNyYy9wdGxpYi9jb21tb24vY29udGFpbi5jeHgub3JpZwkyMDA1LTExLTMwIDEzOjQ3OjQx
LjAwMDAwMDAwMCArMDEwMAorKysgc3JjL3B0bGliL2NvbW1vbi9jb250YWluLmN4eAkyMDA3LTA5
LTI3IDEwOjAxOjQ5LjAwMDAwMDAwMCArMDIwMApAQCAtMjQ2NSw3ICsyNDY1LDcgQEAgUFN0cmlu
ZyAmIFBTdHJpbmc6OnZzcHJpbnRmKGNvbnN0IGNoYXIgKgogICBQQXNzZXJ0KFNldFNpemUoMjAw
MCksIFBPdXRPZk1lbW9yeSk7CiAgIDo6dnNwcmludGYodGhlQXJyYXkrbGVuLCBmbXQsIGFyZyk7
CiAjZWxzZQotICBQSU5ERVggc2l6ZSA9IDA7CisgIFBJTkRFWCBzaXplID0gbGVuOwogICBkbyB7
CiAgICAgc2l6ZSArPSAxMDAwOwogICAgIFBBc3NlcnQoU2V0U2l6ZShzaXplKSwgUE91dE9mTWVt
b3J5KTsK
</data>        

          </attachment>
    </bug>

</bugzilla>