<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>213820</bug_id>
          <alias>CVE-2008-1372</alias>
          <creation_ts>2008-03-18 12:30 0000</creation_ts>
          <short_desc>app-arch/bzip2 &lt;1.0.5 CERT-FI: 20469 Buffer overread (CVE-2008-1372)</short_desc>
          <delta_ts>2008-04-02 21:31:43 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>https://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html</bug_file_loc>
          <status_whiteboard>A3 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>hanno@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>arm@gentoo.org</cc>
    
    <cc>m68k@gentoo.org</cc>
    
    <cc>s390@gentoo.org</cc>
    
    <cc>sh@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-03-18 12:30:45 0000</bug_when>
            <thetext>CERT-FI did a fuzzing tool test and discovered issues in various archiving tools.

bzip2 is vulnerable, fixed in 1.0.5. This code is probably bundled in some other packages.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2008-03-18 13:38:19 0000</bug_when>
            <thetext>ive added 1.0.5 to the tree ... now if only they didnt screw up the packaging of it ...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-18 13:47:14 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=app-arch/bzip2-1.0.5
Target keywords : &quot;alpha amd64 arm hppa ia64 m68k mips ppc ppc64 release s390 sh sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-18 14:16:44 0000</bug_when>
            <thetext>Created an attachment (id=146488)
bzip2-CERT-FI-20469.patch

Just for reference, the patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fmccor@gentoo.org</who>
            <bug_when>2008-03-18 16:31:22 0000</bug_when>
            <thetext>Sparc stable.  All tests pass, it works on my files, and portage can use it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-03-18 17:17:26 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; Sparc stable.  All tests pass, it works on my files, and portage can use it.

That&apos;s odd. Ferris forgot to mark the ebuild. So er, stable for HPPA and SPARC then. :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-03-18 18:28:17 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-03-18 18:30:32 0000</bug_when>
            <thetext>alpha/ia64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2008-03-19 00:34:46 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dirtyepic@gentoo.org</who>
            <bug_when>2008-03-19 01:58:29 0000</bug_when>
            <thetext>there&apos;s no need to cc mips on security stabilization bugs.  we&apos;re ~arch only.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-03-19 19:00:37 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-19 20:53:31 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-21 02:17:53 0000</bug_when>
            <thetext>request filed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-04-02 21:31:43 0000</bug_when>
            <thetext>GLSA 200804-02</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>146488</attachid>
            <date>2008-03-18 14:16 0000</date>
            <desc>bzip2-CERT-FI-20469.patch</desc>
            <filename>bzip2-CERT-FI-20469.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGJ6aXAyLTEuMC40L2J6bGliLmMJMjAwNy0wMS0wMyAwMzowMDo1NS4wMDAwMDAwMDAgKzAx
MDAKKysrIGJ6aXAyLTEuMC41L2J6bGliLmMJMjAwNy0xMi0wOSAxNDo1NzoyMS4wMDAwMDAwMDAg
KzAxMDAKQEAgLTU5OCw2ICs1OTgsNyBAQAogICAgICAgVUludDMyICAgICAgICBjX3RQb3MgICAg
ICAgICAgICAgICA9IHMtPnRQb3M7CiAgICAgICBjaGFyKiAgICAgICAgIGNzX25leHRfb3V0ICAg
ICAgICAgID0gcy0+c3RybS0+bmV4dF9vdXQ7CiAgICAgICB1bnNpZ25lZCBpbnQgIGNzX2F2YWls
X291dCAgICAgICAgID0gcy0+c3RybS0+YXZhaWxfb3V0OworICAgICAgSW50MzIgICAgICAgICBy
b19ibG9ja1NpemUxMDBrICAgICA9IHMtPmJsb2NrU2l6ZTEwMGs7CiAgICAgICAvKiBlbmQgcmVz
dG9yZSAqLwogCiAgICAgICBVSW50MzIgICAgICAgYXZhaWxfb3V0X0lOSVQgPSBjc19hdmFpbF9v
dXQ7Ci0tLSBiemlwMi0xLjAuNC9iemxpYl9wcml2YXRlLmgJMjAwNy0wMS0wMyAwMzowMDo1NS4w
MDAwMDAwMDAgKzAxMDAKKysrIGJ6aXAyLTEuMC41L2J6bGliX3ByaXZhdGUuaAkyMDA3LTEyLTA5
IDE1OjAwOjQ2LjAwMDAwMDAwMCArMDEwMApAQCAtNDQyLDExICs0NDIsMTUgQEAKIC8qLS0gTWFj
cm9zIGZvciBkZWNvbXByZXNzaW9uLiAtLSovCiAKICNkZWZpbmUgQlpfR0VUX0ZBU1QoY2NjYykg
ICAgICAgICAgICAgICAgICAgICBcCisgICAgLyogY190UG9zIGlzIHVuc2lnbmVkLCBoZW5jZSB0
ZXN0IDwgMCBpcyBwb2ludGxlc3MuICovIFwKKyAgICBpZiAocy0+dFBvcyA+PSAoVUludDMyKTEw
MDAwMCAqIChVSW50MzIpcy0+YmxvY2tTaXplMTAwaykgcmV0dXJuIFRydWU7IFwKICAgICBzLT50
UG9zID0gcy0+dHRbcy0+dFBvc107ICAgICAgICAgICAgICAgICBcCiAgICAgY2NjYyA9IChVQ2hh
cikocy0+dFBvcyAmIDB4ZmYpOyAgICAgICAgICAgXAogICAgIHMtPnRQb3MgPj49IDg7CiAKICNk
ZWZpbmUgQlpfR0VUX0ZBU1RfQyhjY2NjKSAgICAgICAgICAgICAgICAgICBcCisgICAgLyogY190
UG9zIGlzIHVuc2lnbmVkLCBoZW5jZSB0ZXN0IDwgMCBpcyBwb2ludGxlc3MuICovIFwKKyAgICBp
ZiAoY190UG9zID49IChVSW50MzIpMTAwMDAwICogKFVJbnQzMilyb19ibG9ja1NpemUxMDBrKSBy
ZXR1cm4gVHJ1ZTsgXAogICAgIGNfdFBvcyA9IGNfdHRbY190UG9zXTsgICAgICAgICAgICAgICAg
ICAgIFwKICAgICBjY2NjID0gKFVDaGFyKShjX3RQb3MgJiAweGZmKTsgICAgICAgICAgICBcCiAg
ICAgY190UG9zID4+PSA4OwpAQCAtNDY5LDggKzQ3MywxMCBAQAogICAgKCgoVUludDMyKXMtPmxs
MTZbaV0pIHwgKEdFVF9MTDQoaSkgPDwgMTYpKQogCiAjZGVmaW5lIEJaX0dFVF9TTUFMTChjY2Nj
KSAgICAgICAgICAgICAgICAgICAgICAgICAgICBcCi0gICAgICBjY2NjID0gQloyX2luZGV4SW50
b0YgKCBzLT50UG9zLCBzLT5jZnRhYiApOyAgICBcCi0gICAgICBzLT50UG9zID0gR0VUX0xMKHMt
PnRQb3MpOworICAgIC8qIGNfdFBvcyBpcyB1bnNpZ25lZCwgaGVuY2UgdGVzdCA8IDAgaXMgcG9p
bnRsZXNzLiAqLyBcCisgICAgaWYgKHMtPnRQb3MgPj0gKFVJbnQzMikxMDAwMDAgKiAoVUludDMy
KXMtPmJsb2NrU2l6ZTEwMGspIHJldHVybiBUcnVlOyBcCisgICAgY2NjYyA9IEJaMl9pbmRleElu
dG9GICggcy0+dFBvcywgcy0+Y2Z0YWIgKTsgICAgXAorICAgIHMtPnRQb3MgPSBHRVRfTEwocy0+
dFBvcyk7CiAKIAogLyotLSBleHRlcm5zIGZvciBkZWNvbXByZXNzaW9uLiAtLSovCg==
</data>        

          </attachment>
    </bug>

</bugzilla>