<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>97651</bug_id>
          
          <creation_ts>2005-07-01 13:26 0000</creation_ts>
          <short_desc>www-apps/egroupware is affected by XML_RPC PHP flaw (CAN-2005-1921)</short_desc>
          <delta_ts>2005-07-10 12:35:32 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B1 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>web-apps@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-01 13:26:58 0000</bug_when>
            <thetext>According to GulfTech advisory egroupware is also affected.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-04 13:21:31 0000</bug_when>
            <thetext>egroupware uses a really old version of what has finally become phpxmlrpc (in
phpgwapi/inc/xml_functions.inc.php). Needs a careful backport too :/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-04 13:37:14 0000</bug_when>
            <thetext>Created an attachment (id=62618)
egroupware.patch

Backported patch from PEAR fix</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-04 13:49:22 0000</bug_when>
            <thetext>web-apps: please bump with patch... and test a little (I didn&apos;t)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>stuart@gentoo.org</who>
            <bug_when>2005-07-05 17:08:26 0000</bug_when>
            <thetext>Patched and rev-bumped.

Best regards,
Stu</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-06 01:17:07 0000</bug_when>
            <thetext>alpha amd64 ppc x86 : please mark stable, this is a really minor (but needed)
bump that shouldn&apos;t break anything.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-07-06 12:57:31 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-07 09:48:17 0000</bug_when>
            <thetext>Arches: please mark stable so that the GLSA on this exploited vuln can go out.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2005-07-08 04:27:16 0000</bug_when>
            <thetext>stable on alpha, thanks kloeri

amd64/x86/web-apps, pls test and mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2005-07-09 07:26:53 0000</bug_when>
            <thetext>Stuart - why is the epatch line in the ebuild commented out?

#   epatch ${FILESDIR}/${PN}-1.0.0.007-xmlrpc.patch</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2005-07-09 07:37:36 0000</bug_when>
            <thetext>back to ebuild status, until the issue in comment #9 is fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2005-07-09 19:02:06 0000</bug_when>
            <thetext>Upstream released a new version. 1.0.0.008 in Portage, marked stable on x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2005-07-09 19:10:28 0000</bug_when>
            <thetext>Recalling alpha and ppc. Arches, please test 1.0.0.008 and mark stable. Note
that this one is late and it&apos;s already being exploited + blocks another GLSA, so
don&apos;t wait too long. Thanks everbody!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2005-07-09 21:37:32 0000</bug_when>
            <thetext>alpha, ppc, x86: i just noticed that you are already marked stable, sorry to
annoy you :( only amd64 left to go.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2005-07-10 12:02:39 0000</bug_when>
            <thetext>Sorry for the delay Stefan. amd64 is stable now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2005-07-10 12:03:10 0000</bug_when>
            <thetext>Should remove us from CC as well :-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2005-07-10 12:05:48 0000</bug_when>
            <thetext>Ready for GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2005-07-10 12:35:32 0000</bug_when>
            <thetext>GLSA 200507-08

thanks everyone</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>62618</attachid>
            <date>2005-07-04 13:37 0000</date>
            <desc>egroupware.patch</desc>
            <filename>egroupware.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGVncm91cHdhcmUvcGhwZ3dhcGkvaW5jL3htbF9mdW5jdGlvbnMuaW5jLnBocC5vbGQJMjAw
NS0wNy0wNCAyMjozNTozOS4wMDAwMDAwMDAgKzAyMDAKKysrIGVncm91cHdhcmUvcGhwZ3dhcGkv
aW5jL3htbF9mdW5jdGlvbnMuaW5jLnBocAkyMDA0LTAzLTA3IDEwOjU1OjQzLjAwMDAwMDAwMCAr
MDEwMApAQCAtMTg5LDcgKzE4OSw3IEBACiAJCQkJJEdMT0JBTFNbJ194aCddWyRwYXJzZXJdWydx
dCddPTA7CiAJCQkJYnJlYWs7CiAJCQljYXNlICdOQU1FJzoKLQkJCQkkR0xPQkFMU1snX3hoJ11b
JHBhcnNlcl1bJ3N0J10gLj0gJyInOworCQkJCSRHTE9CQUxTWydfeGgnXVskcGFyc2VyXVsnc3Qn
XSAuPSAiJyI7CiAJCQkJJEdMT0JBTFNbJ194aCddWyRwYXJzZXJdWydhYyddID0gJyc7CiAJCQkJ
YnJlYWs7CiAJCQljYXNlICdGQVVMVCc6CkBAIC0yNjUsNyArMjY1LDcgQEAKIAkJCQkkR0xPQkFM
U1snX3hoJ11bJHBhcnNlcl1bJ2NtJ10tLTsKIAkJCQlicmVhazsKIAkJCWNhc2UgJ05BTUUnOgot
CQkJCSRHTE9CQUxTWydfeGgnXVskcGFyc2VyXVsnc3QnXS49ICRHTE9CQUxTWydfeGgnXVskcGFy
c2VyXVsnYWMnXSAuICciID0+ICc7CisJCQkJJEdMT0JBTFNbJ194aCddWyRwYXJzZXJdWydzdCdd
Lj0gJEdMT0JBTFNbJ194aCddWyRwYXJzZXJdWydhYyddIC4gIicgPT4gIjsKIAkJCQlicmVhazsK
IAkJCWNhc2UgJ0JPT0xFQU4nOgogCQkJCS8vIHNwZWNpYWwgY2FzZSBoZXJlOiB3ZSB0cmFuc2xh
dGUgYm9vbGVhbiAxIG9yIDAgaW50byBQSFAKQEAgLTI5Myw3ICsyOTMsNyBAQAogCQkJCX0KIAkJ
CQllbHNlaWYgKCRHTE9CQUxTWydfeGgnXVskcGFyc2VyXVsncXQnXT09MikKIAkJCQl7Ci0JCQkJ
CSRHTE9CQUxTWydfeGgnXVskcGFyc2VyXVsnc3QnXS49J2Jhc2U2NF9kZWNvZGUoIicuICRHTE9C
QUxTWydfeGgnXVskcGFyc2VyXVsnYWMnXSAuICciKSc7CisJCQkJCSRHTE9CQUxTWydfeGgnXVsk
cGFyc2VyXVsnc3QnXS49ImJhc2U2NF9kZWNvZGUoJyIuICRHTE9CQUxTWydfeGgnXVskcGFyc2Vy
XVsnYWMnXSAuICInKSI7IAogCQkJCX0KIAkJCQllbHNlaWYgKCRuYW1lPT0nQk9PTEVBTicpCiAJ
CQkJewo=
</data>        

          </attachment>
    </bug>

</bugzilla>