<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>198983</bug_id>
          
          <creation_ts>2007-11-12 22:55 0000</creation_ts>
          <short_desc>www-client/kazehakase &lt; 0.5.0 Multiple issues in embedded PCRE</short_desc>
          <delta_ts>2008-01-30 22:40:20 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/27543/</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>198845</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>matsuu@gentoo.org</cc>
    
    <cc>mozilla@gentoo.org</cc>
    
    <cc>nakano@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-12 22:55:55 0000</bug_when>
            <thetext>Kazehakase ships a copy of PCRE which is vulnerable to several security issues as pointed out in bug #198198.

Version 0.5.0 uses GRegEx as a regular expression engine, so it is unaffected.

Maintainers, please advise on the following questions:
* What is PCRE in Kazehakase used for? Especially: Can inputs come from outside (i.e. bookmark imports)?
* Is 0.5.0 ok for stabling?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>matsuu@gentoo.org</who>
            <bug_when>2007-11-13 05:10:41 0000</bug_when>
            <thetext>pcre is used for incremental search by GRegex. its only enabled with migemo USE flag.
kazehakase-0.5.0 is enough to stable, but it depends on &gt;=x11-libs/gtk+-2.12.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-14 00:01:08 0000</bug_when>
            <thetext>Arches, please test and mark stable www-client/kazehakase-0.5.0.
Target keywords : &quot;amd64 ppc sparc x86&quot;

Please note the comment above, this needs to be done after you&apos;re off of bug 198845.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-11-14 07:56:35 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>astinus@gentoo.org</who>
            <bug_when>2007-11-14 15:31:39 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-11-15 15:12:48 0000</bug_when>
            <thetext>sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-11-18 11:12:24 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-18 14:21:49 0000</bug_when>
            <thetext>I&apos;ll set this [glsa?] because I&apos;m still not sure if it is exploitable by remote attackers - Can someone send trick me into opening a file / link that might lead to execution of code?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-02 12:33:42 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; I&apos;ll set this [glsa?] because I&apos;m still not sure if it is exploitable by remote
&gt; attackers - Can someone send trick me into opening a file / link that might
&gt; lead to execution of code?

Matsuu?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>matsuu@gentoo.org</who>
            <bug_when>2007-12-04 10:33:40 0000</bug_when>
            <thetext>sorry
I checked source code once again, and it seems that PCRE is used for migemo, history, and bookmark.
I&apos;m presently checking with upstream about it.
http://lists.sourceforge.jp/mailman/archives/kazehakase-devel/2007-December/002774.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-12-30 18:39:26 0000</bug_when>
            <thetext>(In reply to comment #9)
&gt; sorry
&gt; I checked source code once again, and it seems that PCRE is used for migemo,
&gt; history, and bookmark.
&gt; I&apos;m presently checking with upstream about it.
&gt; http://lists.sourceforge.jp/mailman/archives/kazehakase-devel/2007-December/002774.html
&gt; 

Any news here? I don&apos;t speak japanese :)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>matsuu@gentoo.org</who>
            <bug_when>2007-12-31 11:04:09 0000</bug_when>
            <thetext>ah, sorry.
in smart bookmark feature, GRegEX is used to body contents. so, perhaps it is exploitable by remote attackers.
http://lists.sourceforge.jp/mailman/archives/kazehakase-devel/2007-December/002775.html
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>matsuu@gentoo.org</who>
            <bug_when>2007-12-31 11:08:17 0000</bug_when>
            <thetext>FYI:
http://www.google.com/translate?u=http%3A%2F%2Flists.sourceforge.jp%2Fmailman%2Farchives%2Fkazehakase-devel%2F2007-December%2F002775.html&amp;langpair=ja%7Cen</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-01-06 18:14:45 0000</bug_when>
            <thetext>I tend to vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-06 23:02:35 0000</bug_when>
            <thetext>YES. filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-01-30 22:40:20 0000</bug_when>
            <thetext>GLSA 200801-18, sorry for the delay.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>