<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>99751</bug_id>
          
          <creation_ts>2005-07-20 22:24 0000</creation_ts>
          <short_desc>sys-libs/zlib: another buffer overflow (CAN-2005-1849)</short_desc>
          <delta_ts>2005-07-21 23:23:16 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0489.html</bug_file_loc>
          <status_whiteboard>A1 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>betelgeuse@gentoo.org</cc>
    
    <cc>wolf31o2@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-07-20 22:24:55 0000</bug_when>
            <thetext>Package : zlib  
 Vulnerability : buffer overflow  
 Problem type : remote DoS  
 Debian-specific: no  
 CVE ID : CAN-2005-1849  
  
Markus Oberhumer discovered a flaw in the way zlib, a library used for  
 file compression and decompression, handles invalid input. This flaw can  
 cause programs which use zlib to crash when opening an invalid file.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-07-20 22:26:31 0000</bug_when>
            <thetext>Base-system please commit the zlib-1.2.3 ebuild for further arch testing. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-07-20 22:28:29 0000</bug_when>
            <thetext>*** Bug 98780 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-07-21 01:41:39 0000</bug_when>
            <thetext>Arches please test and mark zlib-1.2.3 stable.  
  
Committed with the following keywords from previous arch security liaison  
testing:  
  
KEYWORDS=&quot;alpha ~amd64 ~arm hppa ~ia64 ~m68k ~mips ppc ppc64 ~s390 ~sh sparc  
~x86&quot;  
  </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2005-07-21 04:38:39 0000</bug_when>
            <thetext> 21 Jul 2005; Tavis Ormandy &lt;taviso@gentoo.org&gt; +zlib-1.2.3.ebuild:
security bump #63740

The ChangeLog should probably point to this bug?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2005-07-21 04:53:27 0000</bug_when>
            <thetext>I&apos;ll make note when I bump x86 of this bug #</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2005-07-21 05:04:06 0000</bug_when>
            <thetext>stable on x86 made reference to the can and this bug. 
s390 amd64 m68k arm sh mips ia64 remain.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2005-07-21 06:25:23 0000</bug_when>
            <thetext>Actually, this is a &quot;blocker&quot; for the release being built.

Thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>herbs@gentoo.org</who>
            <bug_when>2005-07-21 07:29:11 0000</bug_when>
            <thetext>Stable on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2005-07-21 12:14:53 0000</bug_when>
            <thetext>IA64 done by agriffis</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-07-21 17:27:58 0000</bug_when>
            <thetext>all stable but mips</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2005-07-21 18:31:18 0000</bug_when>
            <thetext>Sadly other distros seem to be down playing the impact of this vuln. 
I glad we have guys like tavis who do homework.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-07-21 22:48:27 0000</bug_when>
            <thetext>GLSA 200507-19 
 
mips don&apos;t forget to mark stable to benifit from the GLSA. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2005-07-21 23:23:16 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>