<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>78620</bug_id>
          
          <creation_ts>2005-01-18 22:19 0000</creation_ts>
          <short_desc>app-office/koffice includes vulnerable xpdf again</short_desc>
          <delta_ts>2005-01-23 06:07:24 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.idefense.com/application/poi/display?id=186&amp;type=vulnerabilities</bug_file_loc>
          <status_whiteboard>B2 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kde@gentoo.org</cc>
    
    <cc>soulse@gmail.com</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-18 22:19:34 0000</bug_when>
            <thetext>koffice includes xpdf code and therefore might be vulnerable CAN-2005-0064.
Please see bug 77888 for details.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-19 00:54:15 0000</bug_when>
            <thetext>KDE team, please bump koffice. Upstream patch is available on bug #77888.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-01-19 04:42:59 0000</bug_when>
            <thetext>&lt;&lt;&lt; koffice-1.3.5-r2.ebuild

herds, please mark stable - would be nice to have it in 2005.0</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2005-01-20 09:51:22 0000</bug_when>
            <thetext>Created an attachment (id=49045)
Patch

According to an email from Waldo Bastian, this is the preferred fix for
koffice&apos;s xpdf problem.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-20 10:07:03 0000</bug_when>
            <thetext>Back to ebuild. Kde please decide which patch you want to use.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-01-20 10:11:27 0000</bug_when>
            <thetext>&quot;Both patches fix the same issue. The koffice patch doesn&apos;t seem to handle the 
keyLength == 0 case though. The koffice patch is the patch that went into 
xpdf upstream.&quot;

is exactly what he said. The question is, if we need to revise the patch for that reason. If it doesn&apos;t matter from the functionality and security perspective, it would only be an issue, if we have another problem, which needs to be patched. Also this affects all ebuilds, which apply the CAN-2005-0064.patch, not only koffice.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-20 10:28:41 0000</bug_when>
            <thetext>Thx Carsten, that will be your head ache on the next xpdf vulnerability:-)

Arches please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-01-20 11:30:12 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>sekretarz@gentoo.org</who>
            <bug_when>2005-01-20 15:06:40 0000</bug_when>
            <thetext>amd64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-01-21 12:38:21 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-01-21 12:40:06 0000</bug_when>
            <thetext>sparc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-01-21 12:51:05 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-22 13:44:29 0000</bug_when>
            <thetext>*** Bug 79135 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-23 06:07:24 0000</bug_when>
            <thetext>GLSA 200501-32</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>49045</attachid>
            <date>2005-01-20 09:51 0000</date>
            <desc>Patch</desc>
            <filename>post-1.3.5-koffice.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IGtvZmZpY2UvZmlsdGVycy9rd29yZC9wZGYveHBkZi94cGRmL1hSZWYuY2MKPT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PQpSQ1MgZmlsZTogL2hvbWUva2RlL2tvZmZpY2UvZmlsdGVycy9rd29yZC9wZGYveHBkZi94
cGRmL1hSZWYuY2MsdgpyZXRyaWV2aW5nIHJldmlzaW9uIDEuNgpyZXRyaWV2aW5nIHJldmlzaW9u
IDEuOApkaWZmIC11IC1wIC1yMS42IC1yMS44Ci0tLSBrb2ZmaWNlL2ZpbHRlcnMva3dvcmQvcGRm
L3hwZGYveHBkZi9YUmVmLmNjCTMwIE9jdCAyMDA0IDE2OjM1OjMzIC0wMDAwCTEuNgorKysga29m
ZmljZS9maWx0ZXJzL2t3b3JkL3BkZi94cGRmL3hwZGYvWFJlZi5jYwkyMCBKYW4gMjAwNSAxNzoz
NjozOCAtMDAwMAkxLjgKQEAgLTUwMSw2ICs1MDEsMTIgQEAgR0Jvb2wgWFJlZjo6Y2hlY2tFbmNy
eXB0ZWQoR1N0cmluZyAqb3duZQogCX0gZWxzZSB7CiAJICBrZXlMZW5ndGggPSA1OwogCX0KKwlp
ZiAoa2V5TGVuZ3RoIDwgMSkgeworCSAga2V5TGVuZ3RoID0gMTsKKwl9CisJaWYgKGtleUxlbmd0
aCA+IDE2KSB7CisJICBrZXlMZW5ndGggPSAxNjsKKwl9CiAJcGVybUZsYWdzID0gcGVybWlzc2lv
bnMuZ2V0SW50KCk7CiAJaWYgKGVuY1ZlcnNpb24gPj0gMSAmJiBlbmNWZXJzaW9uIDw9IDIgJiYK
IAkgICAgZW5jUmV2aXNpb24gPj0gMiAmJiBlbmNSZXZpc2lvbiA8PSAzKSB7Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>