<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>46590</bug_id>
          
          <creation_ts>2004-04-02 05:41 0000</creation_ts>
          <short_desc>&lt;=app-crypt/heimdal-0.6 - Cross-realm trust vulnerability</short_desc>
          <delta_ts>2005-04-10 08:46:08 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>GLSA Errors</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          
          <priority>P1</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>lha@kth.se</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>agriffis@gentoo.org</cc>
    
    <cc>base-system@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>lha@kth.se</who>
            <bug_when>2004-04-02 05:41:11 0000</bug_when>
            <thetext>app-crypt/heimdal needs to be update to heimdal 0.6.1

see http://www.pdc.kth.se/heimdal/advisory/2004-04-01/

Reproducible: Always
Steps to Reproduce:
1. see http://www.pdc.kth.se/heimdal/advisory/2004-04-01/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aescriva@gentoo.org</who>
            <bug_when>2004-04-02 07:55:19 0000</bug_when>
            <thetext>Aron - would you create an ebuild for 0.6.1? Thanks. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-04-07 11:43:41 0000</bug_when>
            <thetext>heimdal-0.6.1 added to portage as
KEYWORDS=&quot;~x86 ~sparc ~ppc ~alpha ~ia64 ~amd64 ~hppa ~mips&quot;

Every version below 0.6(currently stable) has been removed from the tree.

I don&apos;t have krb setup so I have no way of verifying if this package 
runtime environment works. One patch conflicted and seemed unneeded for 
gcc-3.3.x and was thus commented out.

From reading the .ebuild I fail to understand what this sed statement is 
doing other than wasting a few cpu cycles. 
(Maybe it should be sed -i -e)
sed -i &quot;s:LIB_crypt = @LIB_crypt@:LIB_crypt = -lssl @LIB_crypt@:g&quot; Makefile.in || die

Arch maintainers please test and mark stable if/when
ready. Please try test/verify the rumtime as well if you can.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mr_bones_@gentoo.org</who>
            <bug_when>2004-04-07 12:35:18 0000</bug_when>
            <thetext>From the sed info page:

   &quot;If no `-e&apos;, `-f&apos;, `--expression&apos;, or `--file&apos; options are given on
the command-line, then the first non-option argument on the command
line is taken to be the SCRIPT to be executed.&quot;

I prefer to see the -e there myself, but the sed line probably works as intended
without the -e.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2004-04-07 22:09:17 0000</bug_when>
            <thetext>Marked stable on mips.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-04-08 01:54:32 0000</bug_when>
            <thetext>arches.  plztest.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-04-08 07:11:02 0000</bug_when>
            <thetext>Marked stable on Alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>avenj@gentoo.org</who>
            <bug_when>2004-04-08 07:33:59 0000</bug_when>
            <thetext>Stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2004-04-08 09:10:55 0000</bug_when>
            <thetext>Stable on ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-04-08 10:17:25 0000</bug_when>
            <thetext>Stable on sparc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-04-09 01:39:25 0000</bug_when>
            <thetext>Mr Bones (thanks)

Still waiting on x86 and a report that the runtime has been tested.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-04-09 02:33:09 0000</bug_when>
            <thetext>I don&apos;t think we&apos;re going to get a report on the runtime -- not many individual devs use kerberos for authentication.  Also, agriffis hasn&apos;t been responsive at all regarding this issue, so I recommend we bump to stable on x86.

We&apos;ve given folks the opportunity to test -- we need to get this security fix out.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-04-09 03:00:15 0000</bug_when>
            <thetext>pushed to stable on x86.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0371</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-04-09 03:52:07 0000</bug_when>
            <thetext>GLSA 200404-09</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>agriffis@gentoo.org</who>
            <bug_when>2004-04-09 07:23:54 0000</bug_when>
            <thetext>&quot;agriffis hasn&apos;t been responsive at all regarding this issue, so I recommend we bump to stable on x86&quot;

klieber, I don&apos;t use or maintain heimdal.  You asked me about it on IRC, I said, yeah, go ahead and bump it since we don&apos;t know anybody to test...  so I don&apos;t understand your comment.  :-(</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-04-09 07:56:20 0000</bug_when>
            <thetext>sorry -- came across wrong.  that&apos;s what I get for trying to respond to bugs too quickly.  my apologies.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-09-22 21:13:17 0000</bug_when>
            <thetext>ia64 stable</thetext>
          </long_desc>
      
    </bug>

</bugzilla>