<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>218064</bug_id>
          <alias>CVE-2008-1837</alias>
          <creation_ts>2008-04-17 08:16 0000</creation_ts>
          <short_desc>app-arch/unrar-gpl &lt;0.0.1_p20080417 : rar overflow (CVE-2008-1837)</short_desc>
          <delta_ts>2009-07-13 22:36:58 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>INVALID</resolution>
          
          <status_whiteboard>B2 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>hanno@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>hanno@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-04-17 08:16:21 0000</bug_when>
            <thetext>unrar-gpl shares code from libclamav, thus is also affected by CVE-2008-1837.

I can&apos;t reproduce the issue on current cvs snapshot (just committed), thus I assume it&apos;s safe, although it hasn&apos;t seen any updates recently.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-04-17 21:43:07 0000</bug_when>
            <thetext>amd64/x86 stable, last arches.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-18 00:03:16 0000</bug_when>
            <thetext>Hanno, can you please confirm that this is actually fixed? What makes me wonder is that the last CVS commit is 7 months old, and the latest affected clamav version was released only 2 months ago.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hanno@gentoo.org</who>
            <bug_when>2008-04-18 10:53:20 0000</bug_when>
            <thetext>rbu, I&apos;m not really sure, I was wondering the same.

I wrote to the clamav-dev asking for the samples and he sent me three rar-files crashing clamav &lt; 0.93. All three don&apos;t crash latest unrar (while they crash the older snapshot), so from my tests they are safe. I don&apos;t have an explanation for that though.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-18 11:14:11 0000</bug_when>
            <thetext>If you still have contact upstream, you could ask for the patch fixing CVE-2008-1837.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-23 17:12:34 0000</bug_when>
            <thetext>Hanno: The only difference between the two versions you tried was removing &quot;unrar30&quot; code, which is removed from the upstream libclamav for some time. The diff that is called &quot;check in 0.93 patches&quot; is this:
http://svn.clamav.net/websvn/comp.php?repname=clamav-devel&amp;path=&amp;compare%5B%5D=%2Ftrunk%2Flibclamunrar%2F@3787&amp;compare%5B%5D=%2Ftrunk%2Flibclamunrar%2F@3788
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-05-05 21:26:54 0000</bug_when>
            <thetext>any news here?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-11-26 18:10:54 0000</bug_when>
            <thetext>revisiting this bug I noticed that the libclamav code is actually not used within unrar-gpl. The unrar20.* unrar15.* and unrar29.* files are derived from libclamav, but you can simply delete them without any effect. The rar code actually used is the one from unrarlib.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>