<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>195700</bug_id>
          
          <creation_ts>2007-10-13 13:42 0000</creation_ts>
          <short_desc>media-libs/flac &lt; 1.2.1 Media File Processing Integer Overflow Vulnerabilities (CVE-2007-4619)</short_desc>
          <delta_ts>2008-01-10 09:00:58 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/27210/</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>190900</dependson>
    
    <dependson>191277</dependson>
    
    <dependson>191278</dependson>
    
    <dependson>191283</dependson>
    
    <dependson>191286</dependson>
    
    <dependson>191292</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>keytoaster@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>mips@gentoo.org</cc>
    
    <cc>sound@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2007-10-13 13:42:04 0000</bug_when>
            <thetext>Some vulnerabilities have been reported in FLAC, which can be exploited by malicious people to compromise a user&apos;s system.

The vulnerabilities are caused due to integer overflow errors in various components when processing FLAC media files and can be exploited to cause heap-based buffer overflows via specially-crafted FLAC media files.

Successful exploitation allows execution of arbitrary code.

The vulnerabilities are reported in version 1.2.0. Prior versions and other applications using the vulnerable library may also be affected.

Solution:
Update to version 1.2.1.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2007-10-13 13:53:35 0000</bug_when>
            <thetext>Sound, please check whether our latest stable version is also affected.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-17 01:29:26 0000</bug_when>
            <thetext>sound, assuming our current stable is also vulnerable, how do we proceed?
Is 1.2.1* ok to go stable or should we try to fix to 1.1.X ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-10-21 06:08:14 0000</bug_when>
            <thetext>We are stabilizing 1.2.1 but because it has a TEXT RELOCATION patch from PaX Team to go with I _strongly_ advice _every_ arch team to test both encoding and decoding properly. This version is API/ABI compatible with 1.1.4 which was going stable anyway so you _need_ to do bugs depending on this bug first, and yes, that means also _entire_ gstreamer with plugins.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-10-21 06:09:06 0000</bug_when>
            <thetext>*** Bug 191280 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-10-21 06:16:04 0000</bug_when>
            <thetext>Should have mention, it&apos;s media-libs/flac-1.2.1-r1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2007-10-21 16:10:52 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-10-21 19:43:00 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-10-22 05:39:21 0000</bug_when>
            <thetext>Why was RESTRICT=test added?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-10-22 13:59:07 0000</bug_when>
            <thetext>Stable for HPPA and SPARC.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-10-22 14:23:45 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; Why was RESTRICT=test added?
&gt; 

Temporary measure, drac is gonna find the problems and report upstream.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-10-22 17:44:10 0000</bug_when>
            <thetext>Sparc is not stable because reverse dependencies (which this bug depends on) aren&apos;t resolved yet.

20:27 &lt;+CIA-29&gt; jer * gentoo-x86/media-libs/flac/ (ChangeLog flac-1.2.1-r1.ebuild): 
20:27 &lt;+CIA-29&gt; Reverting sparc stabilisation due to reverse dependencies I cannot test.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-10-22 20:25:10 0000</bug_when>
            <thetext>alpha/ia64 stable, thanks Tobias</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-10-23 16:11:36 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-10-24 17:36:41 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-11-01 19:07:04 0000</bug_when>
            <thetext>sparc stable, this is ready for glsa</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-01 19:12:29 0000</bug_when>
            <thetext>request filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-12 21:48:13 0000</bug_when>
            <thetext>GLSA 200711-15</thetext>
          </long_desc>
      
    </bug>

</bugzilla>