<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>214576</bug_id>
          
          <creation_ts>2008-03-24 19:06 0000</creation_ts>
          <short_desc>dev-php5/pecl-apc &lt;=3.0.16 Usage of strcpy in apc.c can cause stack corruption with long filenames (CVE-2008-1488)</short_desc>
          <delta_ts>2008-04-09 09:50:28 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://pecl.php.net/bugs/bug.php?id=13415</bug_file_loc>
          <status_whiteboard>C1 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>hanno@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>gentoobugs@ncode.nl</cc>
    
    <cc>php-bugs@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-03-24 19:06:15 0000</bug_when>
            <thetext>See upstream bug report. No upstream fix yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-24 19:32:08 0000</bug_when>
            <thetext>cve requested via http://thread.gmane.org/gmane.comp.security.oss.general/150</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2008-03-25 23:00:25 0000</bug_when>
            <thetext>3.0.17 InCVS...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-03-26 00:22:01 0000</bug_when>
            <thetext>archs, please stabilize</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-03-26 02:11:52 0000</bug_when>
            <thetext>3.0.17 causes unreliably error 500 messages on my server, so probably needs further investigation.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-26 23:14:31 0000</bug_when>
            <thetext>back to [ebuild] then.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jan.rieger@medialize.de</who>
            <bug_when>2008-03-28 13:18:36 0000</bug_when>
            <thetext>3.0.17 causes segmentation faults, see http://pecl.php.net/bugs/bug.php?id=13511

There is a 3.0.16 ebuild available at http://christian-seiler.de/temp/pecl-apc-3.0.16-CVE-overlay.tar.gz including a patch for CVE-2008-1488 that doesn&apos;t cause segmentation faults for me on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-28 14:07:54 0000</bug_when>
            <thetext>(In reply to comment #6)
&gt; 3.0.17 causes segmentation faults, see
&gt; http://pecl.php.net/bugs/bug.php?id=13511
&gt; 
&gt; There is a 3.0.16 ebuild available at
&gt; http://christian-seiler.de/temp/pecl-apc-3.0.16-CVE-overlay.tar.gz including a
&gt; patch for CVE-2008-1488 that doesn&apos;t cause segmentation faults for me on amd64.

Jan, can you please simply attach the patch (and any non-trivial changes to the ebuild) on this bug? Thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jan.rieger@medialize.de</who>
            <bug_when>2008-03-28 14:20:14 0000</bug_when>
            <thetext>Created an attachment (id=147546)
pecl-apc-3.0.16-CVE-2008-1488.patch

(In reply to comment #7)
&gt; Jan, can you please simply attach the patch (and any non-trivial changes to the
&gt; ebuild) on this bug? Thanks.

Added pecl-apc-3.0.16-CVE-2008-1488.patch

The only addidtion to the ebuild is:

	epatch &quot;${FILESDIR}&quot;/${P}-CVE-2008-1488.patch
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2008-03-28 19:23:55 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; Created an attachment (id=147546) [edit]
&gt; pecl-apc-3.0.16-CVE-2008-1488.patch

3.0.16-r1 committed with this patch; lets give it another try...

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-03-28 21:43:26 0000</bug_when>
            <thetext>amd64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-03-29 13:53:35 0000</bug_when>
            <thetext>Upstream has released 3.0.18 which should fix the .17-problems.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-03-30 10:47:41 0000</bug_when>
            <thetext>sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-03-31 18:50:54 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-03 14:46:27 0000</bug_when>
            <thetext>request filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-09 09:50:28 0000</bug_when>
            <thetext>GLSA 200804-07, thanks.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>147546</attachid>
            <date>2008-03-28 14:20 0000</date>
            <desc>pecl-apc-3.0.16-CVE-2008-1488.patch</desc>
            <filename>pecl-apc-3.0.16-CVE-2008-1488.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGFwYy5jLm9sZAkyMDA4LTAzLTI2IDE5OjIyOjAyLjAwMDAwMDAwMCArMDEwMAorKysgYXBj
LmMJMjAwOC0wMy0yNiAxOToyMjoyMy4wMDAwMDAwMDAgKzAxMDAKQEAgLTMzMSw3ICszMzEsNyBA
QAogICAgICAgICAgICAgLyogbm90OiBbbm8gYWN0aXZlIGZpbGVdIG9yIG5vIHBhdGggKi8KICAg
ICAgICAgICAgIG1lbWNweShmaWxlaW5mby0+ZnVsbHBhdGgsIGV4ZWNfZm5hbWUsIGV4ZWNfZm5h
bWVfbGVuZ3RoKTsKICAgICAgICAgICAgIGZpbGVpbmZvLT5mdWxscGF0aFtleGVjX2ZuYW1lX2xl
bmd0aF0gPSBERUZBVUxUX1NMQVNIOwotICAgICAgICAgICAgc3RyY3B5KGZpbGVpbmZvLT5mdWxs
cGF0aCArZXhlY19mbmFtZV9sZW5ndGggKzEsIGZpbGVuYW1lKTsKKyAgICAgICAgICAgIHN0cmxj
cHkoZmlsZWluZm8tPmZ1bGxwYXRoICtleGVjX2ZuYW1lX2xlbmd0aCArMSwgZmlsZW5hbWUsc2l6
ZW9mKGZpbGVpbmZvLT5mdWxscGF0aCktZXhlY19mbmFtZV9sZW5ndGgtMSk7CiAgICAgICAgICAg
ICAvKiBhcGNfd3ByaW50KCJmaWxlbmFtZTogJXMsIGV4ZWNfZm5hbWU6ICVzLCBmaWxlaW5mby0+
ZnVsbHBhdGg6ICVzIiwgZmlsZW5hbWUsIGV4ZWNfZm5hbWUsIGZpbGVpbmZvLT5mdWxscGF0aCk7
ICovCiAgICAgICAgICAgICBpZiAoYXBjX3N0YXQoZmlsZWluZm8tPmZ1bGxwYXRoLCAmZmlsZWlu
Zm8tPnN0X2J1ZikgPT0gMCkgewogICAgICAgICAgICAgICAgIGZvdW5kID0gMTsK
</data>        

          </attachment>
    </bug>

</bugzilla>