<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>209903</bug_id>
          <alias>CVE-2008-0671</alias>
          <creation_ts>2008-02-12 19:25 0000</creation_ts>
          <short_desc>games-mud/tintin &lt;1.98.0 add_line_buffer Buffer Overflow (CVE-2008-{0671,0672,0673})</short_desc>
          <delta_ts>2009-11-23 17:41:14 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>ASSIGNED</bug_status>
          
          <bug_file_loc>http://aluigi.altervista.org/adv/rintintin-adv.txt</bug_file_loc>
          <status_whiteboard>B1 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>games@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-12 19:25:44 0000</bug_when>
            <thetext>CVE-2008-0671 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0671):
  Stack-based buffer overflow in the add_line_buffer function in TinTin++
  1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code
  via a long chat message, related to conversion from LF to CRLF.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-12 19:31:21 0000</bug_when>
            <thetext>Games herd, did you hear anything upstream about this?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-12 19:32:23 0000</bug_when>
            <thetext>CVE-2008-0672 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0672):
  The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows
  remote attackers to cause a denial of service (application crash) via a YES
  message without a newline character, which triggers a NULL dereference.

CVE-2008-0673 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0673):
  TinTin++ 1.97.9 and WinTin++ 1.97.9 open files on the basis of an inbound
  file-transfer request, before the user has an opportunity to decline the
  request, which allows remote attackers to truncate arbitrary files in the top
  level of a home directory.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mr_bones_@gentoo.org</who>
            <bug_when>2008-02-12 19:45:35 0000</bug_when>
            <thetext>I removed that version from portage.  We&apos;ll pick up normal processing on the next version.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-12 20:43:28 0000</bug_when>
            <thetext>I verified that all three vulnerabilities also affect our stable, so that won&apos;t be enough. :-/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mr_bones_@gentoo.org</who>
            <bug_when>2008-02-12 20:59:13 0000</bug_when>
            <thetext>package masked.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-02-13 17:37:34 0000</bug_when>
            <thetext>maskglsa request filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mr_bones_@gentoo.org</who>
            <bug_when>2008-03-25 04:55:17 0000</bug_when>
            <thetext>added tintin-1.98.0, removed all previous versions, unmasked.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-25 10:23:05 0000</bug_when>
            <thetext>I couldn&apos;t reproduce the errors with 1.98.0, so that looks fine.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mr_bones_@gentoo.org</who>
            <bug_when>2009-11-23 04:28:41 0000</bug_when>
            <thetext>please close this out.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2009-11-23 17:41:14 0000</bug_when>
            <thetext>A GLSA request was filed some time ago and the bug will be closed after it was sent.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>