<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>196978</bug_id>
          <alias>CVE-2007-4476</alias>
          <creation_ts>2007-10-24 23:06 0000</creation_ts>
          <short_desc>app-arch/cpio safer_name_suffix buffer overflow (CVE-2007-4476)</short_desc>
          <delta_ts>2008-01-10 09:02:32 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=441444</bug_file_loc>
          <status_whiteboard>A2? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-24 23:06:46 0000</bug_when>
            <thetext>CVE-2007-4476 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4476):
  Buffer overflow in the safer_name_suffix function in GNU tar has unspecified
  attack vectors and impact, resulting in a &quot;crashing stack.&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-24 23:15:34 0000</bug_when>
            <thetext>Seems like cpio also ships this code. A patch is attached to the Debian bug in URL.

Base-system, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2007-10-28 21:28:35 0000</bug_when>
            <thetext>it isnt a bug in tar or cpio or any package ... the code in question is part of gnulib, so any package that utilizes gnulib&apos;s paxnames.c file is in trouble</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2007-10-28 21:39:46 0000</bug_when>
            <thetext>err, it isnt part of gnulib, it&apos;s part of paxutils ... so any project that imports paxutils is affected ;)

but a quick grep of my /var/log/portage/ (~9000 logs) shows only cpio and tar building up &quot;paxnames.c&quot;

cpio-2.9-r1 in the tree with the code taken from tar-1.19</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-28 23:28:57 0000</bug_when>
            <thetext>Arches, please test and mark stable app-arch/cpio-2.9-r1.
Target keywords : &quot;alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-10-29 10:16:21 0000</bug_when>
            <thetext>alpha/ia64/sparc/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>toralf.foerster@gmx.de</who>
            <bug_when>2007-10-29 13:18:07 0000</bug_when>
            <thetext>(In reply to comment #3)
&gt; but a quick grep of my /var/log/portage/ (~9000 logs) shows only cpio and tar
&gt; building up &quot;paxnames.c&quot;
&gt; 
which lets me to the question whether the tar package should be patched too ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2007-10-29 20:41:40 0000</bug_when>
            <thetext>afaik, tar-1.19 is already fixed ... if someone wants to double check ...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-10-29 21:23:32 0000</bug_when>
            <thetext>This should go to release snapshot</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-29 22:18:43 0000</bug_when>
            <thetext>(In reply to comment #6)
&gt; (In reply to comment #3)
&gt; &gt; but a quick grep of my /var/log/portage/ (~9000 logs) shows only cpio and tar
&gt; &gt; building up &quot;paxnames.c&quot;
&gt; &gt; 
&gt; which lets me to the question whether the tar package should be patched too ?

Only tar &lt;= 1.16 is affected by this, and that&apos;s vulnerable to GLSA 200709-09 anyway.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-10-30 03:29:10 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-10-30 19:07:19 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-10-30 19:34:52 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2007-11-02 19:35:36 0000</bug_when>
            <thetext>Still waiting for amd64 for release... I&apos;d like to bump the priority, but don&apos;t know how that might affect security team rules (and too lazy to look... ;p) so I&apos;m leaving it alone.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tanderson@gentoo.org</who>
            <bug_when>2007-11-02 20:33:29 0000</bug_when>
            <thetext>====amd64====

1. Compiles.
2. Installs.
3. Test all ok.
4. Runs fine as well.

Portage 2.1.3.16 (default-linux/amd64/2007.0/desktop, gcc-4.1.2, glibc-2.6.1-r0, 2.6.22-gentoo-r8 x86_64)
=================================================================
System uname: 2.6.22-gentoo-r8 x86_64 AMD Athlon(tm) 64 Processor 3400+
Timestamp of tree: Fri, 02 Nov 2007 01:47:01 +0000
ccache version 2.4 [enabled]
app-shells/bash:     3.2_p17
dev-java/java-config: 1.3.7, 2.0.33-r1
dev-lang/python:     2.4.4-r6
dev-python/pycrypto: 2.0.1-r6
dev-util/ccache:     2.4-r7
sys-apps/baselayout: 1.12.9-r2
sys-apps/sandbox:    1.2.18.1-r2
sys-devel/autoconf:  2.13, 2.61-r1
sys-devel/automake:  1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.18-r1
sys-devel/gcc-config: 1.3.16
sys-devel/libtool:   1.5.24
virtual/os-headers:  2.6.22-r2
ACCEPT_KEYWORDS=&quot;amd64&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;
CFLAGS=&quot;-march=athlon64 -O2 -pipe&quot;
CHOST=&quot;x86_64-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/revdep-rebuild /etc/terminfo /etc/udev/rules.d&quot;
CXXFLAGS=&quot;-march=athlon64 -O2 -pipe&quot;
DISTDIR=&quot;/distfiles&quot;
FEATURES=&quot;ccache collision-protect distlocks metadata-transfer multilib-strict nostrip parallel-fetch sandbox sfperms strict test unmerge-orphans userfetch&quot;
GENTOO_MIRRORS=&quot;http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo&quot;
MAKEOPTS=&quot;-j2&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --filter=H_**/files/digest-*&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/overlay&quot;
SYNC=&quot;rsync://kv80/gentoo-portage&quot;
USE=&quot;X acl acpi aim alsa amd64 arts berkdb bitmap-fonts branding cairo cli cracklib crypt cups dbus dri dvd dvdread emboss encode esd evo fam firefox fortran gdbm gif gpm gstreamer hal iconv imap ipv6 isdnlog jpeg kde kerberos mad midi mikmod mmx mp3 mpeg mqsli mudflap mysql ncurses nls nptl nptlonly nvidia ogg opengl openmp oss pam pcre pdf perl png pppd python qt3 qt3support quicktime readline reflection sdl session sockets spell spl sqlite3 sse sse2 ssl svg tcpd test tiff truetype truetype-fonts type1-fonts unicode vim vim-syntax vorbis xcomposite xine xml xorg xv zlib&quot; ALSA_CARDS=&quot;ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;keyboard mouse evdev&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;nvidia&quot;
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LDFLAGS, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-04 01:01:12 0000</bug_when>
            <thetext>rPATH is disputing the impact of this:
    Previous versions of the cpio and tar packages are vulnerable to a
    Denial of Service attack in which an attacker can use a malformed
    archive file to cause a stack-based buffer overflow, crashing the
    application.  It is not believed that this vulnerability can be
    exploited to execute malicious code.
Also see: https://issues.rpath.com/browse/RPL-1861

The original Suse description:
     This update fixes a bug in cpio in function safer_name_suffix() which
     leads to a crashing stack. Exploitability is unknown. (CVE-2007-4476)

This leaves us somewhere between A2 and A4. How do we proceed?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-11-05 07:57:22 0000</bug_when>
            <thetext>Stabline doesn&apos;t hurt so I suggest we continue stabling and decide later wether to release a GLSA or not.

If someone have the time to examine this closer now, they&apos;re welcome:-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-11-06 18:42:29 0000</bug_when>
            <thetext>amd64 stable (worked, passed all 4 tests)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-11-06 18:42:45 0000</bug_when>
            <thetext>amd64 stable (worked, passed all 4 tests)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-07 01:27:06 0000</bug_when>
            <thetext>Ready for a vote, see comment #15.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-11-07 09:38:04 0000</bug_when>
            <thetext>I vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-07 19:52:23 0000</bug_when>
            <thetext>yestooGLSArequestfiledkthxbye</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-14 21:45:24 0000</bug_when>
            <thetext>GLSA 200711-18</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2007-11-19 05:57:14 0000</bug_when>
            <thetext>mips got stabled at some point by someone....</thetext>
          </long_desc>
      
    </bug>

</bugzilla>