<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>72521</bug_id>
          
          <creation_ts>2004-11-25 20:31 0000</creation_ts>
          <short_desc>sys-apps/file-4.12 heads up</short_desc>
          <delta_ts>2004-12-14 00:40:27 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A2 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>73786</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-11-25 20:31:46 0000</bug_when>
            <thetext>Stack smashing bug in file/src/readelf.c:donote() mentioned in file&apos;s
changelog does not look so harmless.

--- file-4.10/ChangeLog</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-11-25 20:31:46 0000</bug_when>
            <thetext>Stack smashing bug in file/src/readelf.c:donote() mentioned in file&apos;s
changelog does not look so harmless.

--- file-4.10/ChangeLog 2004-07-25 00:38:54 +0400
+++ file-4.12/ChangeLog 2004-11-24 20:39:06 +0300
@@ -1,3 +1,30 @@
+2004-11-24 12:39  Christos Zoulas  &lt;christos@zoulas.com&gt;
+
+       * Stack smash fix, and ELF more conservative reading.
+         Jakub Bogusz &lt;qboosh@pld-linux.org&gt;
+
+2004-11-20 18:50  Christos Zoulas  &lt;christos@zoulas.com&gt;
+
+       * New FreeBSD version parsing code:
+         Jon Noack &lt;noackjr@alumni.rice.edu&gt;
+
+       * Hackish support for ucs16 strings &lt;christos@zoulas.com&gt;
+
+2004-11-13 03:07  Christos Zoulas  &lt;christos@zoulas.com&gt;
+
+       * print the file name and line number in syntax errors.
+
+2004 10-12 10:50  Christos Zoulas  &lt;christos@zoulas.com&gt;
+
+       * Fix stack overwriting on 0 length strings: Tim Waugh
+           &lt;twaugh@redhat.com&gt; Ned Ludd &lt;solar@gentoo.org&gt;
+
+2004-09-27 11:30  Christos Zoulas  &lt;christos@zoulas.com&gt;
+
+       * Remove 3rd and 4th copyright clause; approved by Ian Darwin.
+
+       * Fix small memory leaks; caught by: Tamas Sarlos 
+           &lt;stamas@csillag.ilab.sztaki.hu&gt;
 
 2004-07-24 16:33  Christos Zoulas  &lt;christos@zoulas.com&gt;
 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-11-26 18:45:58 0000</bug_when>
            <thetext>I&apos;ve already put a new one of these in the tree as ~arch-all</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-29 08:11:52 0000</bug_when>
            <thetext>Waiting for a public disclosure date.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2004-12-07 04:23:21 0000</bug_when>
            <thetext>looks public

http://securitytracker.com/alerts/2004/Dec/1012433.html

&apos;File&apos; Stack Overflow in Processing ELF Headers May Permit Arbitrary Code Execution
SecurityTracker Alert ID:  1012433
SecurityTracker URL:  http://securitytracker.com/id?1012433
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Dec 6 2004

Impact:  Execution of arbitrary code via local system, Execution of arbitrary code via network
Version(s): prior to 4.12
Description:  A vulnerability was reported in &apos;file&apos;. A user may be able to execute arbitrary code on the target system.

Trustix reported a vulnerability in the ELF header parsing code in &apos;file&apos;. A user may be able to create a specially crafted ELF file that, when processed using &apos;file&apos;, may be able to modify the stack and potentially execute arbitrary code.

Impact:  A user may be able to execute arbitrary code on the target system.
Solution:  No solution was available at the time of this entry.
Cause:  Not specified
Underlying OS:  Linux (Any), UNIX (Any)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-12-07 04:56:49 0000</bug_when>
            <thetext>Arches please mark 4.12 stable.

Target KEYWORDS=&quot;alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sh sparc x86&quot;

Note to sh: no arch alias exists so someone (vapier?) please mark it sh.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2004-12-07 06:16:34 0000</bug_when>
            <thetext>sparc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kingtaco@gentoo.org</who>
            <bug_when>2004-12-07 06:33:58 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-12-07 08:32:27 0000</bug_when>
            <thetext>stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2004-12-07 13:13:48 0000</bug_when>
            <thetext>ppc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2004-12-08 01:36:56 0000</bug_when>
            <thetext>mips can&apos;t stable this revision unless we can get the file-4.xx-mips-gentoo.diff patch to apply, otherwise, file gives bad output on mips systems that mess up configure scripts.

The interesting thing is, the patch applies fine outside of portage, but applying within the ebuild, the dry-run sweep creates .orig files that cause epatch to fail on the second pass.  We got a workaround for this?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-12-08 02:29:13 0000</bug_when>
            <thetext>Alpha stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2004-12-08 03:01:28 0000</bug_when>
            <thetext>Okay, disregard Comment #9; seems the patch we use it responsible for the .orig file breaking things.  Will fix &amp;&amp; stabilize in the morning.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2004-12-08 13:14:03 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-12-10 04:50:11 0000</bug_when>
            <thetext>Stable on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-10 08:31:51 0000</bug_when>
            <thetext>ppc64 please mark stable so that the GLSA can go out.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2004-12-10 23:35:29 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-12-12 17:45:15 0000</bug_when>
            <thetext>stable for everyone else now too</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2004-12-13 14:47:19 0000</bug_when>
            <thetext>GLSA 200412-07

thanks everyone</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2004-12-13 20:28:50 0000</bug_when>
            <thetext>lta Magdir/xenix Magdir/xo65 Magdir/xwindows Magdir/zilog Magdir/zyxel; do \
  if test -f ./$frag; then \
    f=./$frag; \
  else \
    f=$frag; \
  fi; \
          cat $f; \
done &gt;&gt; magic
/usr/bin/file -C -m magic
WARNING: type lestring16 &gt;0 Description: %15.15s invalid
file: could not find any magic files!
make[2]: *** [magic.mgc] Error 255
make[2]: Leaving directory `/usr/tmp/portage/file-4.12/work/file-4.12/magic&apos;
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/usr/tmp/portage/file-4.12/work/file-4.12&apos;
make: *** [all] Error 2

!!! ERROR: sys-apps/file-4.12 failed.
!!! Function src_compile, Line 51, Exitcode 2
!!! emake failed
!!! If you need support, post the topmost build error, NOT this status message.

Portage 2.0.51-r3 (hardened/x86, gcc-3.3.2, glibc-2.3.2-r12, 2.4.27-grsec-2.0.1 i686)
=================================================================
System uname: 2.4.27-grsec-2.0.1 i686 Pentium III (Coppermine)
Gentoo Base System version 1.4.3.13
Autoconf: sys-devel/autoconf-2.59-r4
Automake: sys-devel/automake-1.8.3
Binutils: sys-devel/binutils-2.14.90.0.8-r1
Headers:  sys-kernel/linux-headers-2.4.19-r1,sys-kernel/linux-headers-2.4.21-r1
Libtools: sys-devel/libtool-1.5.2-r7
ACCEPT_KEYWORDS=&quot;x86&quot;
AUTOCLEAN=&quot;yes&quot;
CFLAGS=&quot;-march=pentium3 -mcpu=pentium3 -O2 -pipe&quot;
CHOST=&quot;i686-pc-linux-gnu&quot;
COMPILER=&quot;&quot;
CONFIG_PROTECT=&quot;/etc /usr/kde/2/share/config /usr/kde/3/share/config /usr/share/config /usr/share/texmf/dvipdfm/config/ /usr/share/texmf/dvips/config/ /usr/share/texmf/tex/generic/config/ /usr/share/texmf/tex/platex/config/ /usr/share/texmf/xdvi/ /var/qmail/control&quot;
CONFIG_PROTECT_MASK=&quot;/etc/gconf /etc/terminfo /etc/env.d&quot;
CXXFLAGS=&quot;-march=pentium3 -mcpu=pentium3 -O2 -pipe&quot;
DISTDIR=&quot;/usr/local/download/portage/distfiles&quot;
FEATURES=&quot;autoaddcvs ccache distlocks sandbox strict userpriv usersandbox&quot;
GENTOO_MIRRORS=&quot;http://gentoo.osuosl.org http://distro.ibiblio.org/pub/Linux/distributions/gentoo&quot;
MAKEOPTS=&quot;-j2&quot;
PKGDIR=&quot;/usr/portage//packages/x86/&quot;
PORTAGE_TMPDIR=&quot;/usr/tmp&quot;
PORTDIR=&quot;/usr/portage/&quot;
PORTDIR_OVERLAY=&quot;/usr/local/download/portage&quot;
SYNC=&quot;rsync://rsync14.us.gentoo.org/gentoo-portage&quot;
USE=&quot;X509 aalib acl apache2 bcmath berkdb bzlib calendar chroot clamav cpdflib crypt cscope ctype curl curlwrappers dba dbase dbm dbx dio dlloader doc emacs emacs-w3 exif ext-png ext-zlib fam filepro flash flatfile freetds ftp gd gdbm gif gpm guile hardened iconv idea imagemagick imap informix innodb ipalias java javamail javascript jdepend jikes jpeg justify kerberos krb4 lcms libedit libwww maildir mcal mdb mhash migemo mime mmx mnogosearch motif msession mysql mysqli nagios-dns nagios-ntp nagios-ping nagios-ssh ncurses nis nls oav oci8 odbc pam parse-clocks pcntl pdflib perl pg-hier pg-intdatetime pg-vacuumdelay php pic pie plotutils png pnp posix postgres prelude propolice python readline recode ruby samba sasl session sharedmem simplexml skey slang snmp soap sockets spell spl sqlite sse ssl svg sysvipc tcpd tetex tidy tiff tokenizer truetype usb virus-scan wddx wmf x86 xchatnogtk xchattext xface xml xml2 xmlrpc xpm xsl yaz zeo zlib&quot;

sys-apps/file-4.06 is the currently installed version... I&apos;ll test out others...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-12-13 20:53:18 0000</bug_when>
            <thetext>learn to use bugzilla :P (error filed as Bug 73786)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2004-12-13 22:35:42 0000</bug_when>
            <thetext>vapier: That bug is preventing this security bug from being resolved (regardless of whether or not you mark it &apos;RESOLVED&apos; because a secure package is not available to our users who can&apos;t emerge it.

That bug should have been resolved before this was marked stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-12-13 23:44:30 0000</bug_when>
            <thetext>eradicator: I agree this should have been fixed before if we were alerted to the fact that there was a bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2004-12-14 00:20:58 0000</bug_when>
            <thetext>bug #73786: 2004-12-08 04:17 PST
GLSA:       2004-12-13 14:47 PST

The bug was filed 5 days before the GLSA was announced.  base-system should have mentioned this problem here and dealt with it so the GLSA could be released...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-12-14 00:40:27 0000</bug_when>
            <thetext>eradicator: you&apos;re right however base-system is not on this bug and security were only just alerted:

Tue Dec 14 07:35:43 2004</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-12-14 00:40:27 0000</bug_when>
            <thetext>eradicator: you&apos;re right however base-system is not on this bug and security were only just alerted:

Tue Dec 14 07:35:43 2004 

http://bugs.gentoo.org/show_bug.cgi?id=72521


eradicator@gentoo.org changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
  BugsThisDependsOn|                            |73786</thetext>
          </long_desc>
      
    </bug>

</bugzilla>