Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 139593
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Alexander Færøy <ahf@0x90.dk>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 139593 depends on: Show dependency tree
Bug 139593 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-07 12:38 0000
Have a look at this email from bugtraq:
http://www.securityfocus.com/archive/1/439432/30/0/threaded

I'll guess this also effects media-plugins/xmms-adplug

Regards
Alex (eroyf)

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-07-07 13:52:44 0000 -------
Sound please advise. The following is a short summary from URL:


 The library is affected by various heap and stack overflow
 vulnerabilities.
 As intuitable by the types of bugs almost all the unpacking
 instructions don't verify the size of the destination buffers and trust
 in the values provided by the same files which are used for allocating
 the needed buffers (except in the CFF files where it has a fixed size).

------- Comment #2 From Luis Medinas (RETIRED) 2006-07-07 14:13:08 0000 -------
according to the website the fix is in the CVS so i'll wait a few days and see
if the upstream releases a new version. If not i'll patch it.

------- Comment #3 From Sune Kloppenborg Jeppesen 2006-07-07 23:22:44 0000 -------
Thx Luis, setting it to upstream status for now.

------- Comment #4 From Tony Vroon 2006-07-10 16:26:46 0000 -------
Arch teams; please mark audacious 1.1.0 stable as it has a patched AdPlug
backend. (As it does not use an external AdPlug, we do not have to wait for
upstream to release. The necessary patches have been pinched from their CVS and
are already applied.)

------- Comment #5 From Sune Kloppenborg Jeppesen 2006-07-11 00:59:33 0000 -------
Handling audacious stable marking on bug #139957.

------- Comment #6 From Sune Kloppenborg Jeppesen 2006-07-25 12:10:54 0000 -------
Ok a couple of days have passed, changing to ebuild status.

------- Comment #7 From Thierry Carrez (RETIRED) 2006-08-12 07:46:22 0000 -------
(In reply to comment #2)
> according to the website the fix is in the CVS so i'll wait a few days and see
> if the upstream releases a new version. If not i'll patch it.

metalgod, please patch.

------- Comment #8 From Sune Kloppenborg Jeppesen 2006-09-05 06:12:52 0000 -------
Sound, any news on this one?

------- Comment #9 From Luis Medinas (RETIRED) 2006-09-05 10:16:55 0000 -------
From what i saw xmms-adplug isn't affected... it's just a plugin. Since the
main library is fixed the plugin is fine too.

So now we only need to stablize adplug.

Arches please stablize adplug-2.0.1. 
And to be more safe stablize xmms-adplug-1.2 too.

------- Comment #10 From Tobias Scherbaum 2006-09-05 13:02:59 0000 -------
ppc stable

------- Comment #11 From Gustavo Zacarias (RETIRED) 2006-09-05 13:34:14 0000 -------
sparc stable.

------- Comment #12 From Joshua Jackson 2006-09-05 20:57:35 0000 -------
x86 isn't last horray! ^.^

------- Comment #13 From Thomas Cort (RETIRED) 2006-09-06 07:12:37 0000 -------
amd64 stable.

------- Comment #14 From Sune Kloppenborg Jeppesen 2006-09-06 07:38:58 0000 -------
This one is ready for GLSA.

------- Comment #15 From Raphael Marichez 2006-09-12 12:12:50 0000 -------
(In reply to comment #14)
> This one is ready for GLSA.
> 

and this one is done :)

GLSA 200609-06

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug