Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 134960
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tavis Ormandy (RETIRED) <taviso@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 134960 depends on: Show dependency tree
Bug 134960 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-30 14:09 0000
hashcash < 1.21 is apparently vulnerable to a heap overflow

------- Comment #1 From Raphael Marichez 2006-06-11 14:23:07 0000 -------
Hi kloeri, can you provide a new ebuild (-1.21) if needed and possible ? Thanks
in advance.

------- Comment #2 From Stefan Cornelius (RETIRED) 2006-06-13 02:14:28 0000 -------
kloeri please bump, this one is pretty late ...

------- Comment #3 From Bryan Østergaard (RETIRED) 2006-06-14 10:03:08 0000 -------
1.22 in cvs now.

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-06-14 10:45:25 0000 -------
Thx Bryan,

x86 please test and mark stable.

------- Comment #5 From Andrej Kacian (RETIRED) 2006-06-19 13:32:56 0000 -------
x86 stable.

------- Comment #6 From Sune Kloppenborg Jeppesen 2006-06-19 23:46:37 0000 -------
Rerating, feel free to correct if I'm wrong. I'm not too familiar with
hashcash.

------- Comment #7 From Wolf Giesen (RETIRED) 2006-06-20 00:06:12 0000 -------
Without further details available, I'd follow you upping the rating.

------- Comment #8 From Raphael Marichez 2006-06-20 01:25:10 0000 -------
I guess it is a bit like spamassassin or bogofilter.

i've just updated the severity in the draft.

------- Comment #9 From Thierry Carrez (RETIRED) 2006-06-26 12:14:43 0000 -------
Sent as GLSA 200606-25

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug