<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>74384</bug_id>
          
          <creation_ts>2004-12-14 07:31 0000</creation_ts>
          <short_desc>Linux kernel IGMP vulnerabilities (CAN-2004-1137)</short_desc>
          <delta_ts>2009-05-03 13:53:36 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Kernel</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://isec.pl/vulnerabilities/isec-0018-igmp.txt</bug_file_loc>
          <status_whiteboard>[linux &lt;2.6.10]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>christian.korff@gmail.com</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>cycloon@is-root.org</cc>
    
    <cc>dberkholz@gentoo.org</cc>
    
    <cc>hanno@gentoo.org</cc>
    
    <cc>jaervosz@gentoo.org</cc>
    
    <cc>kang@gentoo.org</cc>
    
    <cc>kern-sec@gentoo.org</cc>
    
    <cc>tor.klingberg@gmx.net</cc>

      

      
          <long_desc isprivate="0">
            <who>christian.korff@gmail.com</who>
            <bug_when>2004-12-14 07:31:50 0000</bug_when>
            <thetext>http://isec.pl/vulnerabilities/isec-0019-scm.txt
http://isec.pl/vulnerabilities/isec-0018-igmp.txt</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-14 08:58:06 0000</bug_when>
            <thetext>Separating the two issues. this one will be for the IGMP one :

Synopsis:  Linux kernel IGMP vulnerabilities
Product:   Linux kernel
Version:   2.4 up to and including 2.4.28, 2.6 up to and including 2.6.9
Vendor:    http://www.kernel.org/
URL:       http://isec.pl/vulnerabilities/isec-0018-igmp.txt
CVE:       CAN-2004-1137
Author:    Paul Starzetz &lt;ihaquer@isec.pl&gt;
Date:      Dec 14, 2004

BK changesets :
http://linux.bkbits.net:8080/linux-2.4/cset@41b76e94BsJKm8jhVtyDat9ZM1dXXg
http://linux.bkbits.net:8080/linux-2.6/cset@41b768d1ySHbfa7cUWDle8NjDT_02A
http://linux.bkbits.net:8080/linux-2.6/cset@41b76c07Ee61GkoNwMH-oOvWG2FdxA
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-14 09:03:35 0000</bug_when>
            <thetext>*** Bug 73210 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-12-14 22:19:54 0000</bug_when>
            <thetext>The BK changesets in comment #1 appear to be for isec-0019-scm</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-15 00:41:24 0000</bug_when>
            <thetext>Yes, you&apos;re right... I was confused by those CMSG/IGMP stuff. Latest patch by Chris Wright follows.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-15 00:42:02 0000</bug_when>
            <thetext>Created an attachment (id=46018)
CAN-2004-1137.patch

Patch by Chris Wright (chrisw@osdl.org)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>joker@gentoo.org</who>
            <bug_when>2004-12-15 02:17:00 0000</bug_when>
            <thetext>Any version for 2.4.28 available? Attachment 46018 doesn&apos;t apply on it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tor.klingberg@gmx.net</who>
            <bug_when>2004-12-16 07:18:12 0000</bug_when>
            <thetext>Any fixed version coming to portage?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tor.klingberg@gmx.net</who>
            <bug_when>2004-12-16 07:21:42 0000</bug_when>
            <thetext>Ah, sorry. gentoo-dev-sources-2.6.9-r10 has the fix, but is masked. May I suggest unmasking?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>joker@gentoo.org</who>
            <bug_when>2004-12-16 12:10:08 0000</bug_when>
            <thetext>sparc-sources 2.4.28-r2 are patched</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2004-12-24 07:08:13 0000</bug_when>
            <thetext>Doesn&apos;t affect &lt;= 2.4.21...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tocharian@gentoo.org</who>
            <bug_when>2004-12-24 13:11:15 0000</bug_when>
            <thetext>Patched in ~x86 hardened-sources-2.4.28-r1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2004-12-24 16:35:19 0000</bug_when>
            <thetext>Ok, all patched - the following externally maintained sources still need patching:

gentoo-dev-sources-2.6.7 -- Adding dsd...
hppa(-dev)-sources -- Adding GMSoft...
mips-sources -- Adding `Kumba...
openmosix-sources -- Adding cluster herd...
pegasos-dev-sources -- Adding dholm...
rsbac(-dev)-sources -- Adding kang...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tocharian@gentoo.org</who>
            <bug_when>2004-12-24 17:00:53 0000</bug_when>
            <thetext>hardened-dev-sources-r18 fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2004-12-24 18:51:33 0000</bug_when>
            <thetext>gentoo-dev-sources 2.6.8 (not 2.6.7) is eradicators deal</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2004-12-24 19:22:11 0000</bug_when>
            <thetext>Sorry, sparc is actually on 2.6.9 and already done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dholm@gentoo.org</who>
            <bug_when>2004-12-25 05:29:21 0000</bug_when>
            <thetext>pegasos-dev-sources fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-12-27 06:27:40 0000</bug_when>
            <thetext>2.4 is dropped on hppa and I&apos;ve added 2.6.10-pa1 which doesn&apos;t seems affected by this problem.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>voxus@gentoo.org</who>
            <bug_when>2004-12-27 08:49:24 0000</bug_when>
            <thetext>done in oM6-sources.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2005-01-05 21:21:16 0000</bug_when>
            <thetext>mips-sources fixed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kang@gentoo.org</who>
            <bug_when>2005-01-13 16:04:34 0000</bug_when>
            <thetext>rsbac-dev-sources/rsbac-sources patched</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-01-15 14:49:30 0000</bug_when>
            <thetext>kang: 2.6.10 and 2.4.28-r2 need stabilizing...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kang@gentoo.org</who>
            <bug_when>2005-01-18 13:14:48 0000</bug_when>
            <thetext>Tim Yamin : I&apos;m working on it. Didn&apos;t had inet the past weeks due to a big isp failure.. i just got it back today.
I was able to commit a few things in between ;)
will get that ready before 2005.0 snapshot (luckily isp doesn&apos;t fails tomorrow again ;)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-03-16 03:16:26 0000</bug_when>
            <thetext>Mass-Ccing kern-sec@gentoo.org to make sure Kernel Security guys know about all
of these...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-03-16 06:05:04 0000</bug_when>
            <thetext>All fixed, closing bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2009-05-03 13:53:36 0000</bug_when>
            <thetext>http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=620512af09f33236b4ea04372816b761d48586d9
http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=cfd024d7691544c8b666a7b6aa1e44215775de6b
</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>46018</attachid>
            <date>2004-12-15 00:42 0000</date>
            <desc>Patch (2.4/2.6)</desc>
            <filename>linux-2.6-CAN-2004-1137.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">PT09PT0gbmV0L2lwdjQvaWdtcC5jIDEuNTggdnMgZWRpdGVkID09PT09Ci0tLSAxLjU4L25ldC9p
cHY0L2lnbXAuYyAgICAgICAgMjAwNC0xMS0wOSAxNjo0NDoyNSAtMDg6MDAKKysrIGVkaXRlZC9u
ZXQvaXB2NC9pZ21wLmMgICAgICAyMDA0LTEyLTEwIDE1OjE2OjE3IC0wODowMApAQCAtMTc3OCwx
MiArMTc3OCwxMiBAQCBpbnQgaXBfbWNfc291cmNlKGludCBhZGQsIGludCBvbW9kZSwgc3RyCiAg
ICAgICAgICAgICAgICAgICAgICAgIGdvdG8gZG9uZTsKICAgICAgICAgICAgICAgIHJ2ID0gITA7
CiAgICAgICAgICAgICAgICBmb3IgKGk9MDsgaTxwc2wtPnNsX2NvdW50OyBpKyspIHsKLSAgICAg
ICAgICAgICAgICAgICAgICAgcnYgPSBtZW1jbXAoJnBzbC0+c2xfYWRkciwgJm1yZXFzLT5pbXJf
bXVsdGlhZGRyLAorICAgICAgICAgICAgICAgICAgICAgICBydiA9IG1lbWNtcCgmcHNsLT5zbF9h
ZGRyW2ldLCAmbXJlcXMtPmltcl9zb3VyY2VhZGRyLAogICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgIHNpemVvZihfX3UzMikpOwotICAgICAgICAgICAgICAgICAgICAgICBpZiAocnYgPj0g
MCkKKyAgICAgICAgICAgICAgICAgICAgICAgaWYgKHJ2ID09IDApCiAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgYnJlYWs7CiAgICAgICAgICAgICAgICB9Ci0gICAgICAgICAgICAgICBp
ZiAoIXJ2KSAgICAgICAgLyogc291cmNlIG5vdCBmb3VuZCAqLworICAgICAgICAgICAgICAgaWYg
KHJ2KSAgICAgICAgIC8qIHNvdXJjZSBub3QgZm91bmQgKi8KICAgICAgICAgICAgICAgICAgICAg
ICAgZ290byBkb25lOwogCiAgICAgICAgICAgICAgICAvKiB1cGRhdGUgdGhlIGludGVyZmFjZSBm
aWx0ZXIgKi8KQEAgLTE4MjUsOSArMTgyNSw5IEBAIGludCBpcF9tY19zb3VyY2UoaW50IGFkZCwg
aW50IG9tb2RlLCBzdHIKICAgICAgICB9CiAgICAgICAgcnYgPSAxOyAvKiA+IDAgZm9yIGluc2Vy
dCBsb2dpYyBiZWxvdyBpZiBzbF9jb3VudCBpcyAwICovCiAgICAgICAgZm9yIChpPTA7IGk8cHNs
LT5zbF9jb3VudDsgaSsrKSB7Ci0gICAgICAgICAgICAgICBydiA9IG1lbWNtcCgmcHNsLT5zbF9h
ZGRyLCAmbXJlcXMtPmltcl9tdWx0aWFkZHIsCisgICAgICAgICAgICAgICBydiA9IG1lbWNtcCgm
cHNsLT5zbF9hZGRyW2ldLCAmbXJlcXMtPmltcl9zb3VyY2VhZGRyLAogICAgICAgICAgICAgICAg
ICAgICAgICBzaXplb2YoX191MzIpKTsKLSAgICAgICAgICAgICAgIGlmIChydiA+PSAwKQorICAg
ICAgICAgICAgICAgaWYgKHJ2ID09IDApCiAgICAgICAgICAgICAgICAgICAgICAgIGJyZWFrOwog
ICAgICAgIH0KICAgICAgICBpZiAocnYgPT0gMCkgICAgICAgICAgICAvKiBhZGRyZXNzIGFscmVh
ZHkgdGhlcmUgaXMgYW4gZXJyb3IgKi8KPT09PT0gbmV0L2lwdjYvbWNhc3QuYyAxLjcxIHZzIGVk
aXRlZCA9PT09PQotLS0gMS43MS9uZXQvaXB2Ni9tY2FzdC5jICAgICAgIDIwMDQtMTEtMTEgMTU6
MDc6MjUgLTA4OjAwCisrKyBlZGl0ZWQvbmV0L2lwdjYvbWNhc3QuYyAgICAgMjAwNC0xMi0xMCAx
NzoyMDo0NiAtMDg6MDAKQEAgLTM5MSwxMiArMzkxLDEyIEBAIGludCBpcDZfbWNfc291cmNlKGlu
dCBhZGQsIGludCBvbW9kZSwgc3QKICAgICAgICAgICAgICAgICAgICAgICAgZ290byBkb25lOwog
ICAgICAgICAgICAgICAgcnYgPSAhMDsKICAgICAgICAgICAgICAgIGZvciAoaT0wOyBpPHBzbC0+
c2xfY291bnQ7IGkrKykgewotICAgICAgICAgICAgICAgICAgICAgICBydiA9IG1lbWNtcCgmcHNs
LT5zbF9hZGRyLCBncm91cCwKKyAgICAgICAgICAgICAgICAgICAgICAgcnYgPSBtZW1jbXAoJnBz
bC0+c2xfYWRkcltpXSwgc291cmNlLAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHNp
emVvZihzdHJ1Y3QgaW42X2FkZHIpKTsKLSAgICAgICAgICAgICAgICAgICAgICAgaWYgKHJ2ID49
IDApCisgICAgICAgICAgICAgICAgICAgICAgIGlmIChydiA9PSAwKQogICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgIGJyZWFrOwogICAgICAgICAgICAgICAgfQotICAgICAgICAgICAgICAg
aWYgKCFydikgICAgICAgIC8qIHNvdXJjZSBub3QgZm91bmQgKi8KKyAgICAgICAgICAgICAgIGlm
IChydikgICAgICAgICAvKiBzb3VyY2Ugbm90IGZvdW5kICovCiAgICAgICAgICAgICAgICAgICAg
ICAgIGdvdG8gZG9uZTsKIAogICAgICAgICAgICAgICAgLyogdXBkYXRlIHRoZSBpbnRlcmZhY2Ug
ZmlsdGVyICovCkBAIC00MzcsOCArNDM3LDggQEAgaW50IGlwNl9tY19zb3VyY2UoaW50IGFkZCwg
aW50IG9tb2RlLCBzdAogICAgICAgIH0KICAgICAgICBydiA9IDE7IC8qID4gMCBmb3IgaW5zZXJ0
IGxvZ2ljIGJlbG93IGlmIHNsX2NvdW50IGlzIDAgKi8KICAgICAgICBmb3IgKGk9MDsgaTxwc2wt
PnNsX2NvdW50OyBpKyspIHsKLSAgICAgICAgICAgICAgIHJ2ID0gbWVtY21wKCZwc2wtPnNsX2Fk
ZHIsIGdyb3VwLCBzaXplb2Yoc3RydWN0IGluNl9hZGRyKSk7Ci0gICAgICAgICAgICAgICBpZiAo
cnYgPj0gMCkKKyAgICAgICAgICAgICAgIHJ2ID0gbWVtY21wKCZwc2wtPnNsX2FkZHJbaV0sIHNv
dXJjZSwgc2l6ZW9mKHN0cnVjdCBpbjZfYWRkcikpOworICAgICAgICAgICAgICAgaWYgKHJ2ID09
IDApCiAgICAgICAgICAgICAgICAgICAgICAgIGJyZWFrOwogICAgICAgIH0KICAgICAgICBpZiAo
cnYgPT0gMCkgICAgICAgICAgICAvKiBhZGRyZXNzIGFscmVhZHkgdGhlcmUgaXMgYW4gZXJyb3Ig
Ki8K
</data>        

          </attachment>
    </bug>

</bugzilla>