<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>210317</bug_id>
          
          <creation_ts>2008-02-16 01:57 0000</creation_ts>
          <short_desc>net-misc/nxnode, net-misc/nx Xorg security fixes included</short_desc>
          <delta_ts>2008-04-06 13:33:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.nomachine.com/news-read.php?idnews=230</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>nx@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-16 01:57:30 0000</bug_when>
            <thetext>&quot;NoMachine makes available today the second maintenance release of NX Node 3.1.0. The new packages include minor bug fixes to the NX software and, namely, some security fixes affecting the X11 code-base.&quot;

Seems to be xorg bug 204362.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-16 01:58:53 0000</bug_when>
            <thetext>NX herd, please bump -- or do we have all the necessary code in the tree already? The last ebuild commit is dated before the press release. If so, is it ready for stabling?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>voyageur@gentoo.org</who>
            <bug_when>2008-02-17 22:42:16 0000</bug_when>
            <thetext>This is indeed bug #204362:
&quot;Four of the vulnerabilities affect NX Node 3.1.0-5, namely:

XInput Extension Memory Corruption Vulnerability [IDEF2888 CVE-2007-6427].
TOG-CUP Extension Memory Corruption Vulnerability [IDEF2901 CVE-2007-6428].
EVI Extension Integer Overflow Vulnerability [IDEF2902 CVE-2007-6429].
MIT-SHM Extension Integer Overflow Vulnerability [IDEF2904 CVE-2007-6429]&quot;

Both nxnode and nx packages need to be bumped, I&apos;m adding new versions. 
Stabling packages should also involve net-misc/nxclient-3.1.0 and net-misc/nxserver-freeedition-3.1.0, to go along with new nxnode-3.1.0.

I&apos;ll sum up what needs to be stabled as soon as I have the packages in the tree</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>voyageur@gentoo.org</who>
            <bug_when>2008-02-17 23:12:55 0000</bug_when>
            <thetext>Ok, new packages with security fixes included:
net-misc/nxnode-3.1.0-r2
net-misc/nx-3.1.0-r1
Current stable versions are also based on Xorg, so security stabling is needed


Need amd64 and x86 stable keywords:
net-misc/nxnode-3.1.0-r2
net-misc/nxclient-3.1.0 (ready for stable, to go along with nxnode-3.1)
net-misc/nxserver-freeedition-3.1.0 (same)

x86 stable keyword:
net-misc/nx-3.1.0-r1
net-misc/nxserver-freenx-0.7.1-r2 (ready for stable, has patches with better 3.1 nx detection)

I was about to finally ask amd64 stabling on freenx, I guess it will have to wait a bit more...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-18 04:07:05 0000</bug_when>
            <thetext>Thanks for the fast update, arches please stable as mentioned in the above comment.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-02-18 17:57:22 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-06 08:43:51 0000</bug_when>
            <thetext>I&apos;m working on stabilization of this stuff. But I&apos;ve never used it so this&apos;ll take some time. Hopefully today or tomorrow, I&apos;ll stabilize it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-06 19:59:18 0000</bug_when>
            <thetext>Well while I&apos;m progressing in getting this stuff working I see the following problem with nxnode ebuild. It does:

  chown nx:root &quot;${ROOT}&quot;/usr/NX/etc/node.lic

while it does not create nx user. Also for consistency it&apos;s better to use chown nx:0 ... see bug 103563.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>voyageur@gentoo.org</who>
            <bug_when>2008-03-10 00:58:16 0000</bug_when>
            <thetext>Thanks, the nx user is now created in nxnode (this worked before because the NX install script fixed the ownership in nxserver ebuild), and it&apos;s now nx:0. Should be fine (nxnode-3.1.0-r2)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-19 11:17:02 0000</bug_when>
            <thetext>amd64 stable. After IRC discussion with voyageur I&apos;ve stabilized -r1 for nxnode and nserver-freeedition.

Fixed in release snapshot.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-21 02:19:06 0000</bug_when>
            <thetext>request filed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-06 13:33:02 0000</bug_when>
            <thetext>GLSA 200804-05</thetext>
          </long_desc>
      
    </bug>

</bugzilla>