<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>51460</bug_id>
          
          <creation_ts>2004-05-19 08:50 0000</creation_ts>
          <short_desc>dev-util/cvs&lt;=1.11.15 remote heap overflow</short_desc>
          <delta_ts>2004-06-09 10:26:42 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>GLSA Errors</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://security.e-matters.de/advisories/072004.html</bug_file_loc>
          
          
          <priority>P2</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>n2n@front.ru</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>scandium@gentoo.org</cc>

      

      
          <flag name="Assigned_To"
                status="?"
                setter="koon@gentoo.org"
              requestee="koon@gentoo.org"
          />
          <long_desc isprivate="0">
            <who>n2n@front.ru</who>
            <bug_when>2004-05-19 08:50:38 0000</bug_when>
            <thetext>Application:	CVS feature release &lt;= 1.12.7
CVS stable release &lt;= 1.11.15
Severity:	A vulnerability within CVS allows remote compromise of CVS servers.
Risk:	Critical
Reference:	http://security.e-matters.de/advisories/072004.html
CVE Information: CAN-2004-0396

Workaround: Upstream vendor has supposedly released a patched version.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-19 08:56:16 0000</bug_when>
            <thetext>Fix in 1.11.16
scandium : could you please bump to that version ? Thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-05-19 09:35:20 0000</bug_when>
            <thetext>cvs-1.11.16 is in the tree now, but still ~ on all archs besides x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-05-19 09:40:28 0000</bug_when>
            <thetext>Architecture people, please mark cvs-1.11.16 stable as soon as possible, thank you.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-05-19 10:33:08 0000</bug_when>
            <thetext>Marked stable on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ciaran.mccreesh@googlemail.com</who>
            <bug_when>2004-05-19 12:57:21 0000</bug_when>
            <thetext>sparc, mips done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-05-19 13:04:43 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>avenj@gentoo.org</who>
            <bug_when>2004-05-19 13:22:58 0000</bug_when>
            <thetext>Stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pylon@gentoo.org</who>
            <bug_when>2004-05-19 14:21:12 0000</bug_when>
            <thetext>Stable on ppc.

Our very own cvs-server got already updated, too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-19 14:23:21 0000</bug_when>
            <thetext>Ready for a GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-20 10:01:03 0000</bug_when>
            <thetext>GLSA drafted</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-05-20 11:41:03 0000</bug_when>
            <thetext>GLSA 200405-12</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>randy@gentoo.org</who>
            <bug_when>2004-05-20 18:03:51 0000</bug_when>
            <thetext>Stable on s390</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-05-21 05:00:24 0000</bug_when>
            <thetext>missed ppc64 :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-02 14:17:07 0000</bug_when>
            <thetext>It is still not stable on ia64, ppc64 and arm.

Would be nice if those people could look at it and mark &gt;=1.11.16 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tgall@gentoo.org</who>
            <bug_when>2004-06-02 18:46:41 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-07 16:02:26 0000</bug_when>
            <thetext>ppc64 stabled by tgall
arm stabled by vapier

ia64 still missing :(</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-09 08:15:33 0000</bug_when>
            <thetext>stable on ia64 by agriffis</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-06-09 10:22:50 0000</bug_when>
            <thetext>We might want to hold off on the GLSA on this one. More vulns were found in cvs see bug #53408</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-09 10:26:42 0000</bug_when>
            <thetext>solar, the GLSA for this has already been sent out on May 20th.
(glsa-200405-12)</thetext>
          </long_desc>
      
    </bug>

</bugzilla>