<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>69936</bug_id>
          
          <creation_ts>2004-11-03 04:58 0000</creation_ts>
          <short_desc>kde-base/kdegraphics: kpdf 64bit security issues in xpdf patch</short_desc>
          <delta_ts>2004-11-09 22:09:03 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A2 [glsa] koon</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>69624</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kde@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-03 04:58:50 0000</bug_when>
            <thetext>There was a problem with the recent xpdf-code patch. It introduces another vulnerability on 64-bit platforms.

Patches are posted on bug 69662.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-11-03 09:39:34 0000</bug_when>
            <thetext>&lt;&lt;&lt; kdegraphics-3.2.3-r2.ebuild
&lt;&lt;&lt; kdegraphics-3.3.0-r2.ebuild
&lt;&lt;&lt; kdegraphics-3.3.1-r2.ebuild

Arch herds, please mark stable as necessary to safe our users from evil malicious pdf files flying around everywhere. Thank you.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-11-04 03:54:41 0000</bug_when>
            <thetext>Herds: Apparently the 3.3.0 patch is invalid. I did not care/test, since I don&apos;t have the box to do so in acceptable time. This is no excuse, though. :| If really needed, I&apos;ll fix it, otherwise mark KDE 3.3.1 stable, please.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-11-04 05:46:11 0000</bug_when>
            <thetext>sparc me amadeus</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-11-04 06:08:34 0000</bug_when>
            <thetext>fyi: patch is fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lv@gentoo.org</who>
            <bug_when>2004-11-04 09:42:37 0000</bug_when>
            <thetext>3.3.0-r2 stable on amd64 then</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beljemevanavond@hotmail.com</who>
            <bug_when>2004-11-04 11:13:12 0000</bug_when>
            <thetext>XRef.cc:126: error: no matching function for call to `EmbedStream::EmbedStream(
   Stream*, Object*, int, int&amp;)&apos;
Stream.h:337: error: candidates are: EmbedStream::EmbedStream(const
   EmbedStream&amp;)
Stream.h:340: error:                 EmbedStream::EmbedStream(Stream*, Object*)
XRef.cc:163: error: no matching function for call to `EmbedStream::EmbedStream(
   Stream*, Object*, int, int)&apos;
Stream.h:337: error: candidates are: EmbedStream::EmbedStream(const
   EmbedStream&amp;)
Stream.h:340: error:                 EmbedStream::EmbedStream(Stream*, Object*)
XRef.cc:166: error: no matching function for call to `EmbedStream::EmbedStream(
   Stream*, Object*, int, int)&apos;
Stream.h:337: error: candidates are: EmbedStream::EmbedStream(const
   EmbedStream&amp;)
Stream.h:340: error:                 EmbedStream::EmbedStream(Stream*, Object*)
XRef.cc: In constructor `XRef::XRef(BaseStream*, GString*, GString*)&apos;:
XRef.cc:214: error: `objStr&apos; undeclared (first use this function)
XRef.cc:214: error: (Each undeclared identifier is reported only once for each
   function it appears in.)
XRef.cc:219: error: `getStartXref&apos; undeclared (first use this function)
XRef.cc: At global scope:
XRef.cc:284: error: no `Guint XRef::getStartXref()&apos; member function declared in
   class `XRef&apos;
XRef.cc: In member function `GBool XRef::readXRef(Guint*)&apos;:
XRef.cc:331: error: `readXRefTable&apos; undeclared (first use this function)
XRef.cc:347: error: `readXRefStream&apos; undeclared (first use this function)
XRef.cc: At global scope:
XRef.cc:364: error: no `GBool XRef::readXRefTable(Parser*, Guint*)&apos; member
   function declared in class `XRef&apos;
XRef.cc: In member function `GBool XRef::readXRefTable(Parser*, Guint*)&apos;:
XRef.cc:405: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:405: error: `xrefEntryFree&apos; undeclared (first use this function)
XRef.cc:422: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:422: error: `xrefEntryUncompressed&apos; undeclared (first use this
   function)
XRef.cc:424: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:436: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc: At global scope:
XRef.cc:489: error: no `GBool XRef::readXRefStream(Stream*, Guint*)&apos; member
   function declared in class `XRef&apos;
XRef.cc: In member function `GBool XRef::readXRefStream(Stream*, Guint*)&apos;:
XRef.cc:514: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:553: error: `readXRefStreamSection&apos; undeclared (first use this
   function)
XRef.cc:575: error: no matching function for call to `Object::initDict(Dict*&amp;)&apos;
Object.h:97: error: candidates are: Object* Object::initDict(XRef*)
XRef.cc: At global scope:
XRef.cc:587: error: no `GBool XRef::readXRefStreamSection(Stream*, int*, int,
   int)&apos; member function declared in class `XRef&apos;
XRef.cc: In member function `GBool XRef::readXRefStreamSection(Stream*, int*,
   int, int)&apos;:
XRef.cc:608: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:640: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:645: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:650: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:650: error: `xrefEntryCompressed&apos; undeclared (first use this function)
XRef.cc: In member function `GBool XRef::constructXRef()&apos;:
XRef.cc:748: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:752: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc:756: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
XRef.cc: In member function `Object* XRef::fetch(int, int, Object*)&apos;:
XRef.cc:929: error: &apos;struct XRefEntry&apos; has no member named &apos;type&apos;
make[3]: *** [XRef.lo] Error 1
make[3]: Leaving directory `/var/tmp/portage/kdegraphics-3.3.0-r2/work/kdegraphics-3.3.0/kpdf/xpdf&apos;
make[2]: *** [all-recursive] Error 1
make[2]: Leaving directory `/var/tmp/portage/kdegraphics-3.3.0-r2/work/kdegraphics-3.3.0/kpdf&apos;
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/var/tmp/portage/kdegraphics-3.3.0-r2/work/kdegraphics-3.3.0&apos;
make: *** [all] Error 2

!!! ERROR: kde-base/kdegraphics-3.3.0-r2 failed.
!!! Function kde_src_compile, Line 142, Exitcode 2
!!! died running emake, kde_src_compile:make
!!! If you need support, post the topmost build error, NOT this status message.

This is on x86 architecture.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>sejo@gentoo.org</who>
            <bug_when>2004-11-05 04:15:04 0000</bug_when>
            <thetext>stable on ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-05 04:40:59 0000</bug_when>
            <thetext>Michiel: can you reproduce after a new emerge sync ?
ppc64: please mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2004-11-05 12:27:48 0000</bug_when>
            <thetext>tested and marked stable on ppc64.

Markus</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-06 05:34:14 0000</bug_when>
            <thetext>GLSA 200410-30:02 update out</thetext>
          </long_desc>
      
    </bug>

</bugzilla>