Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 133829
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Harlan Lieberman-Berg (RETIRED) <hlieberman@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 133829 depends on: Show dependency tree
Bug 133829 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-19 18:51 0000
Very large number of buffer overflows exist in cscope <=15.5.  Most deal with
user controlled factors (enviorment variables, filenames), but theoretically,
if someone inserted a carefully managed a #include statement on a largely
distributed source (the kernel, firefox, open office, etc), they could overflow
the buffer on a large number of computers.

------- Comment #1 From Stefan Cornelius (RETIRED) 2006-05-20 07:49:34 0000 -------
vim or emacs herd, please check if we are really vulnerable (seems to be an old
problem) and provide fixed ebuilds in case that we are, thank you.

------- Comment #2 From Thierry Carrez (RETIRED) 2006-05-30 11:09:52 0000 -------
vim/emacs teams: please advise

------- Comment #3 From Matthew Kennedy (RETIRED) 2006-05-30 11:40:33 0000 -------
Can you provide a pointer to the list of vulnerabilities?  I'm not sure what
you're asking -- do you want us to do a code audit?

------- Comment #4 From Thierry Carrez (RETIRED) 2006-05-30 13:29:59 0000 -------
No, was asking if you could provide some insight on that problem, like if you
know about a patch or a new version that we could bump to. 

The closest thing we have to a patch would be in :
http://www.us.debian.org/security/2006/dsa-1064

------- Comment #5 From Matthew Kennedy (RETIRED) 2006-05-30 20:04:51 0000 -------
It is my opinion that our port is vulnerable.  cscope-15.5-r5.ebuild includes
several patches but none of them address the 30+ potential buffer overflows the
debian patch at
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.5-1.1sarge1.diff.gz
addresses.

------- Comment #6 From Stefan Cornelius (RETIRED) 2006-05-31 09:21:18 0000 -------
mkennedy, since you are in the emacs herd and said that we are probably
vulnerable, could you please provide a fixed revbump?

------- Comment #7 From Matthew Kennedy (RETIRED) 2006-05-31 21:04:31 0000 -------
revbumped to cscope-5.15-r6.ebuild w/ the following:

src_unpack() {
        unpack ${A}

        # ~30 buffer overflows fix: Gentoo Bug #133829, patch developed by
        # the Debian Security Team (thanks to those guys), CVE-2004-2541,
        # Moritz Muehlenhoff.  The Debian patch also includes the tempfile
        # fix (previously ${PN}-${PV}-tempfile.patch)
        epatch ${P}-debian-security.patch

------- Comment #8 From Stefan Cornelius (RETIRED) 2006-05-31 21:14:21 0000 -------
arches please test and stable cscope-5.15-r6, thanks

------- Comment #9 From Markus Rothe 2006-05-31 23:45:09 0000 -------
cscope-15.5-r6 stable on ppc64

------- Comment #10 From Thomas Cort (RETIRED) 2006-06-01 10:02:29 0000 -------
alpha stable.

------- Comment #11 From Tobias Scherbaum 2006-06-01 11:13:17 0000 -------
ppc stable

------- Comment #12 From Thomas Cort (RETIRED) 2006-06-01 11:18:38 0000 -------
amd64 stable.

------- Comment #13 From Gustavo Zacarias (RETIRED) 2006-06-01 11:29:44 0000 -------
sparc stable.

------- Comment #14 From Joshua Jackson 2006-06-01 21:09:13 0000 -------
x86 done *~_~*

------- Comment #15 From René Nussbaumer 2006-06-03 02:35:36 0000 -------
stable on hppa

------- Comment #16 From Sune Kloppenborg Jeppesen 2006-06-11 13:20:38 0000 -------
GLSA 200606-10

arm, ia64, mips, s390 don't forget to mark stable to benifit from the GLSA.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug