<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>222823</bug_id>
          
          <creation_ts>2008-05-19 15:22 0000</creation_ts>
          <short_desc>net-libs/gnutls &lt; 2.2.5 Multiple vulnerabilities GNUTLS-SA-2008-1 (CVE-2008-{1948,1949,1950})</short_desc>
          <delta_ts>2008-05-22 10:12:38 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2803</bug_file_loc>
          <status_whiteboard>A1 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>arttuv69@gmail.com</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>arm@gentoo.org</cc>
    
    <cc>corsair@gentoo.org</cc>
    
    <cc>crypto@gentoo.org</cc>
    
    <cc>m68k@gentoo.org</cc>
    
    <cc>s390@gentoo.org</cc>
    
    <cc>sh@gentoo.org</cc>
    
    <cc>special@dereferenced.net</cc>

      

      
          <long_desc isprivate="0">
            <who>arttuv69@gmail.com</who>
            <bug_when>2008-05-19 15:22:17 0000</bug_when>
            <thetext>GNUTLS-SA-2008-1 reported vulnerabilities have been patched in GnuTLS version 2.2.4 released today.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2008-05-19 15:31:31 0000</bug_when>
            <thetext>Thanks for reporting.

Maintainer, please bump.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>special@dereferenced.net</who>
            <bug_when>2008-05-20 00:01:39 0000</bug_when>
            <thetext>Should be dealt with quickly; there are three seperate remotely triggerable (prior to authentication) crash bugs fixed in this release, and at least two of them will affect almost any server application using GnuTLS. Should update to 2.2.5 rather than 2.2.4 - it fixes an issue introduced when fixing these vulnerabilities.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-20 02:18:23 0000</bug_when>
            <thetext>It is currently unclear whether these bugs could be exploited to execute arbitrary code, so until that is clear, we should handle it as A1.

dragonheart, since alonbl unfortunately is retiring, can you bump this package?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-20 11:53:27 0000</bug_when>
            <thetext>https://www.cert.fi/haavoittuvuudet/advisory-gnutls.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2008-05-20 13:41:34 0000</bug_when>
            <thetext>+gnutls-2.2.3.ebuild</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2008-05-20 14:12:38 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; +gnutls-2.2.3.ebuild
&gt; 
er - +gnutls-2.2.5.ebuild :-)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-05-20 14:29:01 0000</bug_when>
            <thetext>Which should go stable, then?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-20 14:37:04 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=net-libs/gnutls-2.2.5
Target keywords : &quot;alpha amd64 arm hppa ia64 m68k ppc ppc64 release s390 sh sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-05-20 15:20:13 0000</bug_when>
            <thetext>Might help to put a copy in distfiles-local quickly.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-20 15:35:13 0000</bug_when>
            <thetext>(In reply to comment #9)
&gt; Might help to put a copy in distfiles-local quickly.

Done. The josefsson.org is incredibly slow.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-05-20 16:02:47 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>superfranky@gmx.at</who>
            <bug_when>2008-05-20 17:50:42 0000</bug_when>
            <thetext>guys, there&apos;s somthing wrong with the configure options in gnutls-2.2.x!

---snip----
local myconf
        use bindist &amp;&amp; myconf=&quot;--disable-lzo&quot; || myconf=&quot;$(use_enable lzo)&quot;
---snip----

--disable-lzo should be --without-lzo, otherwise it&apos;s a UNRECOGNIZED option,
and (use_enable lzo) should be (use_with lzo).

Shall i open a new bug report? Just discovered the issue.

FranKY</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-05-20 19:08:43 0000</bug_when>
            <thetext>alpha/ia64/sparc/x86 stable.

Franz, please open a new bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-05-20 19:16:07 0000</bug_when>
            <thetext>Thanks for spotting this Franz:

./configure --prefix=/usr --host=powerpc64-unknown-linux-gnu --mandir=/usr/share/man --infodir=/usr/share/info --datadir=/usr/share --sysconfdir=/etc --localstatedir=/var/lib --without-included-opencdk --with-zlib --with-lzo --enable-nls --disable-guile --disable-gtk-doc --enable-lzo --libdir=/usr/lib64 --build=powerpc64-unknown-linux-gnu
configure: WARNING: Unrecognized options: --enable-lzo

the error is from the redundant entrys --enable-lzo and --with-lzo.

src_compile() logic is broken. it does first &quot;use bindist &amp;&amp; myconf=&quot;--disable-lzo&quot; || myconf=&quot;$(use_enable lzo)&quot;&quot; and then &quot;econf [...] $(use_with lzo)&quot;

I removed the redundant one after econf and changed use_enable to use_with in the bindist line. I also changed --disable-lzo to --without-lzo.

ppc64 stable by the way.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rich0@gentoo.org</who>
            <bug_when>2008-05-21 15:11:53 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-05-21 16:21:49 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-05-21 21:57:51 0000</bug_when>
            <thetext>GLSA 200805-20</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-05-22 10:12:38 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>