<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>219203</bug_id>
          <alias>CVE-2008-1927</alias>
          <creation_ts>2008-04-24 21:48 0000</creation_ts>
          <short_desc>dev-lang/perl &lt; 5.8.8-r5 UTF-8 regex heap-based buffer overflow (CVE-2008-1927)</short_desc>
          <delta_ts>2008-05-21 21:03:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454792</bug_file_loc>
          <status_whiteboard>A2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>arm@gentoo.org</cc>
    
    <cc>fmccor@gentoo.org</cc>
    
    <cc>m68k@gentoo.org</cc>
    
    <cc>perl@gentoo.org</cc>
    
    <cc>s390@gentoo.org</cc>
    
    <cc>sh@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-24 21:48:21 0000</bug_when>
            <thetext>CVE-2008-1927 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1927):
  Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to
  cause a denial of service (memory corruption and crash) via a crafted regular
  expression containing UTF8 characters.  NOTE: this issue might only be
  present on certain operating systems.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-24 21:55:19 0000</bug_when>
            <thetext>See the Debian bug for details, patch is in the 5.8 stable branch and to be released as 5.8.9.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-05-09 15:48:24 0000</bug_when>
            <thetext>(In reply to comment #1)
&gt; See the Debian bug for details, patch is in the 5.8 stable branch and to be
&gt; released as 5.8.9.
&gt; 

*ping*</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tove@gentoo.org</who>
            <bug_when>2008-05-10 14:32:57 0000</bug_when>
            <thetext>I&apos;ve commited patched ebuilds for perl and libperl:

=dev-lang/perl-5.8.8-r5
=sys-devel/libperl-5.8.8-r2

I&apos;ve used the patch from debian and tested with:
&lt;http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=test.pl;att=2;bug=454792&gt;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tove@gentoo.org</who>
            <bug_when>2008-05-14 08:21:23 0000</bug_when>
            <thetext>(In reply to comment #2)
&gt; (In reply to comment #1)
&gt; &gt; See the Debian bug for details, patch is in the 5.8 stable branch and to be
&gt; &gt; released as 5.8.9.
&gt; &gt; 
&gt; 
&gt; *ping*

*pong* -- see comment #3</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-05-14 09:13:13 0000</bug_when>
            <thetext>(In reply to comment #3)
&gt; I&apos;ve commited patched ebuilds for perl and libperl:
&gt; 
&gt; =dev-lang/perl-5.8.8-r5
&gt; =sys-devel/libperl-5.8.8-r2
&gt; 

Arches, please test and mark stable.
Target &quot;alpha amd64 arm hppa ia64 m68k ~mips ppc ppc64 release s390 sh sparc ~sparc-fbsd x86 ~x86-fbsd</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-05-14 14:21:42 0000</bug_when>
            <thetext>t/op/filetest.............................Can&apos;t locate Config_heavy.pl in @INC (@INC
contains: ../lib) at ../lib/Config.pm line 66.
# Looks like you planned 10 tests but ran 5.
FAILED--expected 10 tests, saw 5

Nevertheless, both stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fmccor@gentoo.org</who>
            <bug_when>2008-05-14 14:25:47 0000</bug_when>
            <thetext>Sparc stable for both.  All tests seem good on sparc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-05-14 15:52:47 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-05-14 17:10:25 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-05-14 20:15:16 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-05-15 09:41:09 0000</bug_when>
            <thetext>alpha/ia64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-05-16 19:20:57 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-05-17 10:42:51 0000</bug_when>
            <thetext>glsa request filed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-05-18 15:24:02 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-18 15:59:24 0000</bug_when>
            <thetext>not quite fixed ;-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2008-05-21 21:03:02 0000</bug_when>
            <thetext>GLSA 200805-17</thetext>
          </long_desc>
      
    </bug>

</bugzilla>