<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>50208</bug_id>
          
          <creation_ts>2004-05-06 05:18 0000</creation_ts>
          <short_desc>app-crypt/heimdal : Kerberos 4 buffer overrun in kadmin</short_desc>
          <delta_ts>2004-09-22 21:32:33 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>GLSA Errors</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.pdc.kth.se/heimdal/advisory/2004-05-06/</bug_file_loc>
          
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>tobias@weisserth.de</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-05-06 05:18:40 0000</bug_when>
            <thetext>All releases prior to 0.6.2 have a possible buffer overrun problem in the Kerberos 4 kadmin compatibility module. It would probably be possible to implement a remote exploit for this, depending on architechture.

http://www.pdc.kth.se/heimdal/advisory/2004-05-06/
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:09.kadmind.asc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-06 13:19:03 0000</bug_when>
            <thetext>CAN-2004-0434
C1 type -&gt; major, target delay 5 days
upstream fix available : version 0.6.2
no maintainer

solar : you did the last bump, can you do it again ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-10 05:07:45 0000</bug_when>
            <thetext>v0.6.2 in portage, thanks to aliz
arches: please test app-crypt/heimdal-0.6.2 and mark stable
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-05-10 19:47:08 0000</bug_when>
            <thetext>Testing here looks good, though fetchmail&apos;s configure script cannot find what it needs for kerberos5 support with heimdal-0.6.2.  Not sure if this worked previously or not.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-05-11 17:30:23 0000</bug_when>
            <thetext>Marked stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-05-12 15:54:35 0000</bug_when>
            <thetext>Marked stable on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-05-13 20:02:18 0000</bug_when>
            <thetext>So do we really care about the fact that fetchmail doesn&apos;t work here or not?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-19 12:46:57 0000</bug_when>
            <thetext>*** Bug 51493 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-19 12:49:20 0000</bug_when>
            <thetext>Noone is sure it was working before. I would say &quot;mark stable&quot; so that the GLSA can go out. Then someone can enter the bug in case it&apos;s a regression...

arches : please mark stable or refute :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-05-19 15:20:38 0000</bug_when>
            <thetext>Okey dokey.  This might be a situation to add into the security policy.  Marked stable on sparc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-21 01:00:06 0000</bug_when>
            <thetext>x86,ppc,mips,amd64,ia64 : please mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jhuebel@gentoo.org</who>
            <bug_when>2004-05-25 11:30:12 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-26 10:56:35 0000</bug_when>
            <thetext>Still missing app-crypt/heimdal-0.6.2 stable on x86, mips and ia64...
x86 : we are waiting for you to issue the GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rphillips@gentoo.org</who>
            <bug_when>2004-05-26 16:41:24 0000</bug_when>
            <thetext>marked stable on x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-27 02:03:30 0000</bug_when>
            <thetext>Heimdal is ready to go</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2004-05-27 02:25:38 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-27 05:29:02 0000</bug_when>
            <thetext>GLSA 200405-23</thetext>
          </long_desc>
      
    </bug>

</bugzilla>