Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 74406

Summary: app-text/acroread mailListIsPdf() Buffer Overflow Vulnerability
Product: Gentoo Security Reporter: Sune Kloppenborg Jeppesen (RETIRED) <jaervosz>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: aarni.honka, carlo, printing
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://www.idefense.com/application/poi/display?id=161&type=vulnerabilities
Whiteboard: B2 [glsa] jaervosz
Package list:
Runtime testing required: ---

Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-12-14 10:25:06 UTC
Buffer overflow in mailListIsPDF().

Official note here:

http://www.adobe.com/support/techdocs/331153.html
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2004-12-14 10:26:41 UTC
*** Bug 74408 has been marked as a duplicate of this bug. ***
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-12-14 10:28:34 UTC
Printing please bump to 5.0.10
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-12-15 04:12:21 UTC
*** Bug 74467 has been marked as a duplicate of this bug. ***
Comment 4 Heinrich Wendel (RETIRED) gentoo-dev 2004-12-15 07:02:53 UTC
bumped to 5.010 and marked stable on x86
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-12-15 07:21:11 UTC
Thx Heinrich,
Did 5.0.9 have other keywords?
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-12-15 07:43:54 UTC
Ok, lewk reports that stable marking is the same as before.

Heinrich please note that when you remove all old ebuilds.

This one is ready for GLSA.
Comment 7 Carsten Lohrke (RETIRED) gentoo-dev 2004-12-15 13:13:38 UTC
its not ready: app-text/acroread-5.010  <  app-text/acroread-5.09 
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-12-15 14:08:04 UTC
Thx Carsten, back to ebuild status.

Printing please fix.
Comment 9 Heinrich Wendel (RETIRED) gentoo-dev 2004-12-15 14:50:10 UTC
really? well 5.0.10 is also smaller,any suggestions?
Comment 10 Thierry Carrez (RETIRED) gentoo-dev 2004-12-16 01:29:48 UTC
suggestion : 5.10 ?

I know it's borked, but Adobe won't release a 5.1.0 since Acrobat6 is out there, so it would work...
Comment 11 Heinrich Wendel (RETIRED) gentoo-dev 2004-12-16 04:48:08 UTC
ok, done
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2004-12-16 07:15:19 UTC
Ready for GLSA, I would say
Comment 13 Luke Macken (RETIRED) gentoo-dev 2004-12-16 15:51:21 UTC
GLSA 200412-12