<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>217609</bug_id>
          
          <creation_ts>2008-04-14 09:42 0000</creation_ts>
          <short_desc>media-plugins/gst-plugins-speex &lt;0.10.7-r1 speex implementations insufficient boundary checks</short_desc>
          <delta_ts>2008-04-17 12:17:29 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          <status_whiteboard>B2 []</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>217715</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>vorlon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>media-video@gentoo.org</cc>
    
    <cc>ssuominen@gentoo.org</cc>
    
    <cc>zaheerm@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-04-14 09:42:00 0000</bug_when>
            <thetext>This bug is not public yet, please do not disclose any information.

gst-plugins-good appears to include vulnerable speex code

see http://www.ocert.org/advisories/ocert-2008-2.html
as well as bug 216499 and bug 217373 for similar issues</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-04-14 09:48:12 0000</bug_when>
            <thetext>patch is available:
http://webcvs.freedesktop.org/gstreamer/gst-plugins-good/ext/speex/gstspeexdec.c?r1=1.40&amp;r2=1.41</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-14 16:03:25 0000</bug_when>
            <thetext>I wonder how this affects media-plugins/gst-plugins-speex</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2008-04-14 17:08:34 0000</bug_when>
            <thetext>+*gst-plugins-speex-0.10.7-r1 (14 Apr 2008)
+
+  14 Apr 2008; Samuli Suominen &lt;drac@gentoo.org&gt;
+  +files/gst-plugins-speex-0.10.7-sec.patch,
+  +gst-plugins-speex-0.10.7-r1.ebuild:
+  Fix for security #217609.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2008-04-14 17:09:44 0000</bug_when>
            <thetext>gst-plugins-speex is a &quot;gentoo split&quot; from -good, so that&apos;s where it should be patched

and for arches, http://samples.mplayerhq.hu/A-codecs/speex/talk109-q5.spx, a sample file</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-14 17:26:54 0000</bug_when>
            <thetext>Arch Security Liaisons, please test and mark stable:
=media-plugins/gst-plugins-speex-0.10.7-r1
Target keywords : &quot;ppc ppc64 release sparc&quot;

CC&apos;ing current Liaisons:
     ppc : dertobi123
   ppc64 : corsair
 release : pva
   sparc : fmccor
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-04-14 18:36:07 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2008-04-14 19:16:46 0000</bug_when>
            <thetext>corsair, fmccor, and others. because this needs gstreamer 0.10.17, make sure you stable also newer version of gst-plugins-ugly, 0.10.6-r1 or newer is OK. this is to avoid blockers, repoman won&apos;t reveal this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fmccor@gentoo.org</who>
            <bug_when>2008-04-14 19:46:07 0000</bug_when>
            <thetext>Sparc stable for gst-plugins-speex &lt;0.10.7-r1.
This requires also sparc stable for:
 gstreamer-0.10.7
 gst-plugins-base-0.10.7
 gst-plugins-ugly-10.6-r1
All done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-04-17 09:42:12 0000</bug_when>
            <thetext>now public via http://www.ocert.org/advisories/ocert-2008-004.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-04-17 10:19:11 0000</bug_when>
            <thetext>This will be fixed with the speex update in bug 217715, keeping open until the
GLSA has been released.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-17 12:17:29 0000</bug_when>
            <thetext>speex has been sent as GLSA 200804-17, this also fixes this bug.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>