<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>53408</bug_id>
          
          <creation_ts>2004-06-09 07:02 0000</creation_ts>
          <short_desc>dev-util/cvs More vulnerabilities</short_desc>
          <delta_ts>2004-06-13 08:47:03 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://security.e-matters.de/advisories/092004.html</bug_file_loc>
          <status_whiteboard>B1 [stable]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>scandium@gentoo.org</cc>
    
    <cc>wschlich@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-06-09 07:02:10 0000</bug_when>
            <thetext>Stefan Esser discovered more bugs in CVS see link for further info.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-06-09 07:06:41 0000</bug_when>
            <thetext>    Advisory: More CVS remote vulnerabilities
 Release Date: 2004/06/09
Last Modified: 2004/06/09
       Author: Stefan Esser [s.esser@e-matters.de]

  Application: CVS feature release &lt;= 1.12.8
               CVS stable release  &lt;= 1.11.16
     Severity: Vulnerabilities within CVS allow remote compromise of
               CVS servers.
         Risk: Critical
Vendor Status: Vendor has released bugfixed versions.
    Reference: http://security.e-matters.de/advisories/092004.html
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-06-09 07:14:57 0000</bug_when>
            <thetext>*** Bug 53411 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-06-09 08:37:48 0000</bug_when>
            <thetext>From: 	Stefan Esser &lt;s.esser@e-matters.de&gt;
To: 	Ned Ludd &lt;solar@gentoo.org&gt;
Subject: 	Re: [Full-Disclosure] Advisory 09/2004: More CVS remote vulnerabilities
Date: 	Wed, 9 Jun 2004 17:19:11 +0200	
&gt; For the sake of clarity could you state exactly which version(s) are
&gt; fixed.
&gt; 
&gt; cvshome seems to have no &gt;=1.11.17 for a stable branch.
&gt; 

The problem is that a coordinated release was planned for today 13:00 GMT
but obvioulsy Derek Robert Price forgot to put them up. Meanwhile I have
heard that within the next 60 minutes the new versions are out.

Stefan Esser</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-09 08:41:34 0000</bug_when>
            <thetext>I will immediatly test and put it into the tree then.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-09 10:56:46 0000</bug_when>
            <thetext>cvs-1.11.17 committed.
Stable on x86, ~ on all other architectures.

Please test and mark stable asap, I&apos;d like to remove &lt;=1.11.16 from the tree then.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-06-09 11:28:30 0000</bug_when>
            <thetext>Stable on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ciaran.mccreesh@googlemail.com</who>
            <bug_when>2004-06-09 12:19:09 0000</bug_when>
            <thetext>mips, sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-09 12:23:16 0000</bug_when>
            <thetext>CAN numbers :

CAN-2004-0414 - no-null-termination of &quot;Entry&quot; lines
CAN-2004-0416 - error_prog_name &quot;double-free()&quot;
CAN-2004-0417 - Argument integer overflow
CAN-2004-0418 - serve_notify() out of bounds writes</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jmaynard@gentoo.org</who>
            <bug_when>2004-06-09 12:34:25 0000</bug_when>
            <thetext>Stable on Alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2004-06-09 12:53:52 0000</bug_when>
            <thetext>stable on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2004-06-09 14:12:21 0000</bug_when>
            <thetext>Marked ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-06-09 17:22:56 0000</bug_when>
            <thetext>Note that if you have the doc useflag set, the ebuild will currently fail to download all of the files as the .ps version of the cederqvist doc redirects you to a secure website.  Even though wget was built with ssl support, it gives the following error;

&gt;&gt;&gt; Downloading http://ccvs.cvshome.org/files/documents/19/196/cederqvist-1.11.17.ps
https: Unknown host


Granted this isn&apos;t a show stopper but I thought people should be aware.  I&apos;m not on the CC so if you want to reply to me either add me or do it offline.  Cheers</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-09 17:36:28 0000</bug_when>
            <thetext>wget http://ccvs.cvshome.org/files/documents/19/196/cederqvist-1.11.17.ps

The above works for me.
I also dislike cvs&apos; new site which changed directory paths so each file has its own number and the redirect to https/443 but I&apos;m afraid currently we can&apos;t do much about it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-10 02:28:30 0000</bug_when>
            <thetext>The ebuild in CVS is still ~amd64. I suppose the stable keyword was lost somewhere.
amd64 please confirm...

Once amd64 is confirmed the GLSA is ready to go.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2004-06-10 03:14:43 0000</bug_when>
            <thetext>Confirming... i&apos;m just still wondering why and how i forgot to commit ?!?
[I double checked, it&apos;s really in now ;-) ]</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-06-10 12:55:49 0000</bug_when>
            <thetext>glsa 200406-06</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-10 13:07:04 0000</bug_when>
            <thetext>Still not stable on arm, ia64, ppc64 and s390.

Will hunt down some individuals now ;-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-10 13:16:46 0000</bug_when>
            <thetext>stable on arm and ia64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>scandium@gentoo.org</who>
            <bug_when>2004-06-13 08:47:03 0000</bug_when>
            <thetext>cvs-1.11.17 stable on all architectures now</thetext>
          </long_desc>
      
    </bug>

</bugzilla>