Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 118550
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
post-3.4.3-kdelibs-kjs.diff post-3.4.3-kdelibs-kjs.diff patch Carsten Lohrke 2006-01-17 12:01 0000 1.53 KB Details | Diff
kdelibs-3.4.3-r1.ebuild kdelibs-3.4.3-r1.ebuild text/plain Carsten Lohrke 2006-01-17 12:02 0000 3.40 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 118550 depends on: Show dependency tree
Bug 118550 blocks: 119737

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-01-10 09:55 0000
Quoting Dirk Mueller: 

>We're planning to release this advisory at the end of next week. It is 
>currently not publically known, treat it with care. 


1. Systems affected:

        KDE 3.2.0 up to including KDE 3.5.0


2. Overview:

        Maksim Orlovich discovered an incorrect bounds check in kjs,
        the Javascript interpreter engine used by Konqueror and other
        parts of KDE, that allows a heap based buffer overflow
        when decoding invalid utf8 encoded URI sequences.


3. Impact:

        Remotely supplied Javascript code can perform a heap overflow
        and crash the web browser or execute arbitrary code.

------- Comment #1 From Stefan Cornelius (RETIRED) 2006-01-10 10:14:52 0000 -------
carlo, as it seems you are also in the kde herd. Will you do the bumping or who
should be added to CC to fix this?

------- Comment #2 From Carsten Lohrke 2006-01-10 10:31:07 0000 -------
I'll take care.

------- Comment #3 From Carsten Lohrke 2006-01-17 12:01:26 0000 -------
Created an attachment (id=77368) [details]
post-3.4.3-kdelibs-kjs.diff

------- Comment #4 From Carsten Lohrke 2006-01-17 12:02:09 0000 -------
Created an attachment (id=77369) [details]
kdelibs-3.4.3-r1.ebuild

------- Comment #5 From Carsten Lohrke 2006-01-17 12:08:04 0000 -------
cc'ing arch guys for testing and Chris as release coordinator. Advisory should
be out end of the week, as long as it isn't don't spread the patch, please.

------- Comment #6 From Chris Gianelloni (RETIRED) 2006-01-17 12:21:51 0000 -------
How soon on this?  We are planning on doing the release snapshot on Friday
(20060120).  This can be injected into the snapshot later, of course.  I'm just
trying to get an idea of the timetable.

------- Comment #7 From Michael Hanselmann (hansmi) (RETIRED) 2006-01-17 12:32:47 0000 -------
I'm no longer the security contact for hppa and ppc. Added KillerFox (hppa) and
dertobi123 (ppc).

------- Comment #8 From Sune Kloppenborg Jeppesen 2006-01-17 12:36:06 0000 -------
Chris AFAIK the end of the week is the best information I have.

Arch security liaisons please test and report back on this bug.

------- Comment #9 From Carsten Lohrke 2006-01-17 12:38:42 0000 -------
Missed alpha. :)

Chris: End of the week. I have no idea if the announcement will be released
before or on the 20th or if they shove it on the next monday. That's why I
cc'ed you.

------- Comment #10 From René Nussbaumer 2006-01-17 13:09:27 0000 -------
Adding gmsoft, because he has allready kdelibs merged.

------- Comment #11 From René Nussbaumer 2006-01-17 13:15:56 0000 -------
Looks good on hppa

------- Comment #12 From Tobias Scherbaum 2006-01-18 08:17:46 0000 -------
Looks good on ppc.

------- Comment #13 From Markus Rothe 2006-01-18 08:32:53 0000 -------
looks good on ppc64: compiles and runs fine. is there an testcase given
anywhere?

------- Comment #14 From Mark Loeser 2006-01-18 19:53:40 0000 -------
Seems fine on x86.

------- Comment #15 From Jose Luis Rivero (yoswink) 2006-01-19 13:40:51 0000 -------
Looks good on alpha.

------- Comment #16 From Sune Kloppenborg Jeppesen 2006-01-19 22:23:21 0000 -------
Please commit with the following stable keywords:

alpha, hppa, ppc, ppc64, x86

amd64 and sparc please test and mark stable.

------- Comment #17 From Chris Gianelloni (RETIRED) 2006-01-20 06:25:17 0000 -------
Removing myself from the list (I'm on x86).

------- Comment #18 From Jason Wever (RETIRED) 2006-01-20 06:28:01 0000 -------
sparc looks fine, please commit with a stable sparc keyword as well

------- Comment #19 From Stefan Cornelius (RETIRED) 2006-01-20 06:38:39 0000 -------
Would somebody actually commit this ebuild? And what about the other versions
of kde in portage 3.4.1, 3.4.2 and 3.5.0? They seem to be affected but i cant
find a new ebuild for them?

------- Comment #20 From Carsten Lohrke 2006-01-20 07:00:19 0000 -------
Committed.


(In reply to comment #13)
> is there an testcase given anywhere?

Unfortunately not.

(In reply to comment #19)
> And what about the other versions of kde in portage 3.4.1, 3.4.2 and 3.5.0? 

KDE 3.5 is not stable, so it's not relevant for stable testing. I committed a
new ebuild revision of course. Users of the stable tree have to use KDE 3.4.3.

------- Comment #21 From Marcus D. Hanwell 2006-01-20 07:23:36 0000 -------
Stable on amd64 too.

------- Comment #22 From Markus Rothe 2006-01-20 08:08:57 0000 -------
this was commited as stable on ppc64. removing us from CC.

------- Comment #23 From Gustavo Zacarias (RETIRED) 2006-01-20 11:03:22 0000 -------
Carlo did the commit for us, so we're off the CC.

------- Comment #24 From Tavis Ormandy (RETIRED) 2006-01-20 12:00:13 0000 -------
*** Bug 119728 has been marked as a duplicate of this bug. ***

------- Comment #25 From René Nussbaumer 2006-01-20 14:02:45 0000 -------
Removed hppa from CC. Allready stable.

------- Comment #26 From Chris Gianelloni (RETIRED) 2006-01-20 14:10:11 0000 -------
x86 is already marked stable...

------- Comment #27 From Tobias Scherbaum 2006-01-20 22:27:37 0000 -------
ppc already stable ...

------- Comment #28 From Stefan Cornelius (RETIRED) 2006-01-21 05:59:13 0000 -------
removing alpha from CC, they seem to be already stable in the ebuild - ready
for glsa.

------- Comment #29 From Marcelo Goes 2006-01-21 13:16:39 0000 -------
Just in time for slashdot... :-)
http://it.slashdot.org/it/06/01/21/0936249.shtml

------- Comment #30 From Sune Kloppenborg Jeppesen 2006-01-22 06:52:48 0000 -------
GLSA 200601-11

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug