Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 127326
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
kaffeine-input-http.patch kaffeine-input-http.patch patch Sune Kloppenborg Jeppesen 2006-03-23 09:16 0000 3.37 KB Details | Diff
kaffeine-0.7.1-r1.ebuild kaffeine-0.7.1-r1.ebuild text/plain Diego E. 'Flameeyes' Pettenò 2006-03-24 13:46 0000 1.22 KB Details
kaffeine-0.7.1-input-http.patch kaffeine-0.7.1-input-http.patch patch Diego E. 'Flameeyes' Pettenò 2006-03-24 13:47 0000 3.38 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 127326 depends on: Show dependency tree
Bug 127326 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-03-23 09:15 0000
KDE Security Advisory: Kaffeine buffer overflow
Original Release Date: 2006-03-XX
URL: http://www.kde.org/info/security/advisory-200603XX-1.txt

0. References
        CAN-2006-XXXX


1. Systems affected:

        Kaffeine up to including Kaffeine 0.7.1


2. Overview:

        Kaffeine contains an unchecked buffer while creating HTTP
        request headers for fetching remote RAM playlists, which
        allow overflowing a heap allocated buffer and execute 
        arbitrary code.


3. Impact:

        Remotely supplied RAM playlists can be used to execute arbitrary
        code on the client machine.


4. Solution:

        Source code patches have been made available which fix these
        vulnerabilities. Contact your OS vendor / binary package provider
        for information about how to obtain updated binary packages.


5. Patch:

        Patch for Kaffeine 0.7.x is available from 
        ftp://ftp.kde.org/pub/kde/security_patches :

        03e74434799159a41d735118916b2dd6  kaffeine-input-http.patch


6. Credits:

        We'd like to thank Marcus Meissner for discovering and reporting
        the issue.

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-03-23 09:16:28 0000 -------
Created an attachment (id=82941) [details]
kaffeine-input-http.patch

------- Comment #2 From Sune Kloppenborg Jeppesen 2006-03-23 09:20:13 0000 -------
CC'ing flameeyes and carlo.

Please don't commit anything to Portage yet, instead attach any updated ebuilds
to this bug and we'll call arch security liaisons to test.

------- Comment #3 From Diego E. 'Flameeyes' Pettenò 2006-03-24 13:46:59 0000 -------
Created an attachment (id=83042) [details]
kaffeine-0.7.1-r1.ebuild

Take it as -r1 or name it as -r2, this is the ebuild..

------- Comment #4 From Diego E. 'Flameeyes' Pettenò 2006-03-24 13:47:31 0000 -------
Created an attachment (id=83043) [details]
kaffeine-0.7.1-input-http.patch

This patch is needed because the other doesn't apply cleanly on source tarball.

------- Comment #5 From Sune Kloppenborg Jeppesen 2006-03-24 23:30:38 0000 -------
Arch Security Liaisons please test and report back on this bug. Do NOT put
anything in Portage at this point.

amd64 -> blubb
ppc -> dertobi123
ppc64 -> corsair
x86 -> halcy0n

------- Comment #6 From Diego E. 'Flameeyes' Pettenò 2006-03-26 05:43:48 0000 -------
FWIW, ~arch is fixed as I've just added version 0.8 that does not seem to use
that code anymore.

------- Comment #7 From Markus Rothe 2006-03-27 01:12:37 0000 -------
0.8 works fine on my ppc64 machine. should we go ahead and mark stable? (as it
is already in ~arch)

------- Comment #8 From Diego E. 'Flameeyes' Pettenò 2006-03-28 11:12:48 0000 -------
No, 0.8 has too many new features yet to be tested, starting from that ripping
interface I don't trust at all.

I'd rather add a 0.7.1-r2 if required.

------- Comment #9 From Diego E. 'Flameeyes' Pettenò 2006-04-02 17:31:46 0000 -------
It's 20060403 (UTC) now, what's the status of this?

------- Comment #10 From Mark Loeser 2006-04-03 09:22:49 0000 -------
Sorry about the delay, the 0.7.1 version looks fine for x86

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-04-03 22:01:04 0000 -------
No announcement yet on the main KDE site.

Arch Security Liaisons please test and report back.

------- Comment #12 From Diego E. 'Flameeyes' Pettenò 2006-04-04 00:01:55 0000 -------
blubb gave me the ok for amd64 as long as it worked there.

ppc and ppc64?

------- Comment #13 From Stefan Cornelius (RETIRED) 2006-04-04 06:03:46 0000 -------
public now

------- Comment #14 From Mark Loeser 2006-04-04 09:20:58 0000 -------
If anything else is needed from x86, please contact tsunam.  I'll be gone until
Friday.

------- Comment #15 From Markus Rothe 2006-04-04 10:44:48 0000 -------
stable on ppc64

------- Comment #16 From Tobias Scherbaum 2006-04-05 11:25:51 0000 -------
ppc stable, sorry for the delay

------- Comment #17 From Sune Kloppenborg Jeppesen 2006-04-05 14:14:09 0000 -------
GLSA drafted, Security please review.

------- Comment #18 From Sune Kloppenborg Jeppesen 2006-04-05 14:32:39 0000 -------
Thx everyone.

GLSA 200604-04

------- Comment #19 From Eduardo Tongson 2006-04-09 15:15:22 0000 -------
*** Bug 129390 has been marked as a duplicate of this bug. ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug