Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 142248
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 142248 depends on: Show dependency tree
Bug 142248 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-31 00:58 0000
Text from Security Focus:

http://www.securityfocus.com/bid/19110/

GnuPG is prone to a remote buffer-overflow vulnerability because it fails to
properly bounds-check user-supplied input before copying it to an
insufficiently
sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the
context of the affected application, but this has not been confirmed.

GnuPG version 1.4.4 is vulnerable to this issue; previous versions may also be
affected.

The following Perl command demonstrates this issue by crashing the affected
application:

perl -e 'print "\xfd\xff\xff\xff\xff\xfe"'| /var/gnupg/bin/gpg --no-armor

http://lists.immunitysec.com/pipermail/dailydave/2006-July/003354.html

------- Comment #1 From Wolf Giesen (RETIRED) 2006-07-31 03:03:16 0000 -------
Actually, 1.9.20-r3 is stable on almost all arches; I also remember we dropped
the last "--no-armor" vulnerability (#137622), but impact is high this time and
might thus call for masking.

------- Comment #2 From Daniel Black 2006-07-31 17:48:29 0000 -------
Added 1.4.5rc1. This seems to fix the vulnerability HOWEVER please wait until
full release before stabilising. It shouldn't be that long and big ugly "THIS
IS A DEVELOPMENT VERSION!" warnings will put people off.

$ gpg --version
gpg (GnuPG) 1.4.5rc1-ecc0.1.6

$ perl -e 'print "\xfd\xff\xff\xff\xff\xfe"'|  gpg  --no-armor
gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
gpg: It is only intended for test purposes and should NOT be
gpg: used in a production environment or with production keys!
gpg: using character set `iso-8859-1'
gpg: packet(61) too large

------- Comment #3 From Stefan Cornelius (RETIRED) 2006-08-01 10:51:45 0000 -------
(In reply to comment #2)
> Added 1.4.5rc1. This seems to fix the vulnerability HOWEVER please wait until
> full release before stabilising. It shouldn't be that long and big ugly "THIS
> IS A DEVELOPMENT VERSION!" warnings will put people off.

Indeed, 1.4.5 has been released. Please do your magic again, thanks

------- Comment #4 From Daniel Black 2006-08-01 14:13:25 0000 -------
1.4.5 magic done.

------- Comment #5 From Andrej Kacian (RETIRED) 2006-08-01 15:43:45 0000 -------
x86 stable, the mentioned perl command doesn't crash it, and the common
functionality checks out OK.

------- Comment #6 From Markus Rothe 2006-08-01 23:14:49 0000 -------
ppc64 stable

------- Comment #7 From Thierry Carrez (RETIRED) 2006-08-02 06:24:29 0000 -------
This could be considered B1 since feeding emails to gpg is somewhat automated.

------- Comment #8 From Raphael Marichez 2006-08-02 06:52:18 0000 -------
(In reply to comment #7)
> This could be considered B1 since feeding emails to gpg is somewhat automated.
> 

i agree

------- Comment #9 From Gustavo Zacarias (RETIRED) 2006-08-02 07:05:10 0000 -------
sparc stable.

------- Comment #10 From Thomas Cort (RETIRED) 2006-08-02 07:33:33 0000 -------
alpha stable.

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-08-02 08:45:27 0000 -------
Rerating according to comment #7 and #8.

------- Comment #12 From Tobias Scherbaum 2006-08-02 09:02:13 0000 -------
ppc stable

------- Comment #13 From René Nussbaumer 2006-08-04 05:45:07 0000 -------
Stable on hppa. Sorry for the delay.

------- Comment #14 From Mike Doty 2006-08-04 06:19:53 0000 -------
amd64 stable

------- Comment #15 From Sune Kloppenborg Jeppesen 2006-08-05 04:51:03 0000 -------
GLSA 200608-08

arm, ia64, mips, s390 don't forget to mark stable to benifit from the GLSA.

------- Comment #16 From Peter Volkov 2008-03-06 09:39:28 0000 -------
Does not affect current (2008.0) release. Removing release.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug