<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>213889</bug_id>
          
          <creation_ts>2008-03-19 05:41 0000</creation_ts>
          <short_desc>app-arch/p7zip &lt; 4.5.7 - CERT-FI and CPNI Joint Vulnerability Advisory on Archive Formats</short_desc>
          <delta_ts>2008-04-09 17:16:41 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>https://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html</bug_file_loc>
          <status_whiteboard>B3? [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jer@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>radek@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-03-19 05:41:25 0000</bug_when>
            <thetext>From the advisory:

   &quot;The vulnerabilities described in this advisory can potentially affect 
    programs that handle the archive formats ACE, ARJ, BZ2, CAB, GZ, LHA,
    RAR, TAR, ZIP and ZOO.&quot;

Ignore the libarchive advisory for Gentoo - that&apos;s ancient. What certainly appears to be needed is for the older app-arch/p7zip-4.55-r1 to be removed (perhaps patched?).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-19 11:32:54 0000</bug_when>
            <thetext>4.57 that is marked as not vulnerable by CERT-FI is in the tree and stable, since january and march, see bug 207520 and bug 213595.

Removal of the affected versions would be nice, but is up to the maintainer. For us, this now poses the question whether we send a GLSA. I&apos;ll inquire upstream about impact.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2008-03-21 11:23:24 0000</bug_when>
            <thetext>removed 4.55* from portage. 

who should close the bug now?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-21 12:27:44 0000</bug_when>
            <thetext>We will, as soon as we know what the scope of the vulnerability is.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-01 17:17:23 0000</bug_when>
            <thetext>Quoting upstream:
I don&apos;t remember exact things that were fixed according that Test Suite. Maybe
I&apos;ve fixed some things, maybe not.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-04-08 21:33:10 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; Quoting upstream:
&gt; I don&apos;t remember exact things that were fixed according that Test Suite. Maybe
&gt; I&apos;ve fixed some things, maybe not.
&gt; 

great :/
I&apos;d be in favor of just closing this without GLSA... so voting NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2008-04-09 17:16:41 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; (In reply to comment #4)
&gt; &gt; Quoting upstream:
&gt; &gt; I don&apos;t remember exact things that were fixed according that Test Suite. Maybe
&gt; &gt; I&apos;ve fixed some things, maybe not.
&gt; &gt; 
&gt; 
&gt; great :/
&gt; I&apos;d be in favor of just closing this without GLSA... so voting NO.


OK, let&apos;s say &quot;fixed&quot;.

</thetext>
          </long_desc>
      
    </bug>

</bugzilla>