<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>59341</bug_id>
          
          <creation_ts>2004-08-04 00:42 0000</creation_ts>
          <short_desc>net-mail/ripmime Attachment Extraction Bypass</short_desc>
          <delta_ts>2004-08-13 06:33:22 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/12201/</bug_file_loc>
          <status_whiteboard>B4 [glsa?]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>gregf@gentoo.org</cc>
    
    <cc>vapier@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-04 00:42:25 0000</bug_when>
            <thetext>CHANGES---------------------------------------------------------------
Fri Jul 30 2004
	- PLD:REL:21H06
		!!!!URGENT RELEASE!!!!
		Released 1.3.2.3

		There&apos;s viruses going around exploiting the ability to hide the 
		majority of their data in an attachment by using blank lines and
		other tricks to make scanning systems prematurely terminate their
		base64 decoding.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-08-04 08:05:36 0000</bug_when>
            <thetext>gregf : please bump ripmime package to version 1.3.2.3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-07 08:16:58 0000</bug_when>
            <thetext>Bumping 1.3.1.2 emerges fine.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-12 09:25:39 0000</bug_when>
            <thetext>seems like gregf is on vacation. Mike would you look into this?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-08-13 05:56:54 0000</bug_when>
            <thetext>added 1.3.2.3 to portage but i dont think this warrants a GLSA

i tested it on x86/ppc/sparc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-13 06:33:22 0000</bug_when>
            <thetext>Thx Mike. 

All arches marked stable.

Closing with no GLSA.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>