Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 155782
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
mod_auth_kerb-5.0-CVE-2006-5989.patch http://modauthkerb.cvs.sourceforge.net/modauthkerb/mod_auth_kerb/spnegokrb5/der_get.c?r1=1.1&r2=1.1.2.1 patch Christian Heim (RETIRED) 2007-01-10 21:32 0000 559 bytes Details | Diff
mod_auth_kerb-5.0-axps1.patch-25129.out mod_auth_kerb-5.0-axps1.patch-25129.out text/plain Andrej Kacian (RETIRED) 2007-01-13 16:08 0000 3.18 KB Details
merge.log merge log text/plain Andrej Kacian (RETIRED) 2007-01-13 22:48 0000 13.07 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 155782 depends on: Show dependency tree
Bug 155782 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-11-20 09:04 0000
Bah, upstream bugs are restricted. Details should be here:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=206736
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=215443

Please don't open this bug before the upstream bugs are opened.

------- Comment #1 From Matthias Geerdsen 2006-12-13 04:33:35 0000 -------
finally adding maintiners
please provide an updated ebuild

RH published an advisory about a week ago

http://rhn.redhat.com/errata/RHSA-2006-0746.html
http://secunia.com/advisories/23023/

------- Comment #2 From Christian Heim (RETIRED) 2007-01-10 21:32:25 0000 -------
Created an attachment (id=106454) [details]
http://modauthkerb.cvs.sourceforge.net/modauthkerb/mod_auth_kerb/spnegokrb5/der_get.c?r1=1.1&r2=1.1.2.1

Proposed patch by UPSTREAM.

------- Comment #3 From Christian Heim (RETIRED) 2007-01-10 22:02:03 0000 -------
(In reply to comment #1)
> finally adding maintiners
> please provide an updated ebuild

New revisions in the tree. Both =net-www/mod_auth_kerb-5.0_rc6-r1 and
=net-www/mod_auth_kerb-5.0_rc7-r1 fix this bug.

------- Comment #4 From Raphael Marichez 2007-01-12 22:12:52 0000 -------
Hello my dear prefered arch. Please test and mark stable one of these two
ebuilds:
=net-www/mod_auth_kerb-5.0_rc6-r1
=net-www/mod_auth_kerb-5.0_rc7-r1 ,
thanks in advance

------- Comment #5 From Andrej Kacian (RETIRED) 2007-01-13 16:06:43 0000 -------
>>> Emerging (2 of 2) net-www/mod_auth_kerb-5.0_rc7-r1 to /
 * mod_auth_kerb-5.0rc7.tar.gz MD5 ;-) ...                                     
  [ ok ]
 * mod_auth_kerb-5.0rc7.tar.gz RMD160 ;-) ...                                  
  [ ok ]
 * mod_auth_kerb-5.0rc7.tar.gz SHA1 ;-) ...                                    
  [ ok ]
 * mod_auth_kerb-5.0rc7.tar.gz SHA256 ;-) ...                                  
  [ ok ]
 * mod_auth_kerb-5.0rc7.tar.gz size ;-) ...                                    
  [ ok ]
 * checking ebuild checksums ;-) ...                                           
  [ ok ]
 * checking auxfile checksums ;-) ...                                          
  [ ok ]
 * checking miscfile checksums ;-) ...                                         
  [ ok ]
 * checking mod_auth_kerb-5.0rc7.tar.gz ;-) ...                                
  [ ok ]
>>> Unpacking source...
>>> Unpacking mod_auth_kerb-5.0rc7.tar.gz to /var/tmp/portage/portage/net-www/mod_auth_kerb-5.0_rc7-r1/work
 * Applying mod_auth_kerb-5.0-CVE-2006-5989.patch ...                          
  [ ok ]
 * Applying mod_auth_kerb-5.0-gcc4.patch ...                                   
  [ ok ]
 * Applying mod_auth_kerb-5.0-axps1.patch ...

 * Failed Patch: mod_auth_kerb-5.0-axps1.patch !
 *  (
/usr/gentoo/portage/net-www/mod_auth_kerb/files/mod_auth_kerb-5.0-axps1.patch )
 *
 * Include in your bugreport the contents of:
 *
 *  
/var/tmp/portage/portage/net-www/mod_auth_kerb-5.0_rc7-r1/temp/mod_auth_kerb-5.0-axps1.patch-25129.out


!!! ERROR: net-www/mod_auth_kerb-5.0_rc7-r1 failed.
Call stack:
  ebuild.sh, line 1593:   Called dyn_unpack
  ebuild.sh, line 731:   Called src_unpack
  mod_auth_kerb-5.0_rc7-r1.ebuild, line 43:   Called epatch
'/usr/gentoo/portage/net-www/mod_auth_kerb/files/mod_auth_kerb-5.0-axps1.patch'
  eutils.eclass, line 341:   Called die

!!! Failed Patch: mod_auth_kerb-5.0-axps1.patch!
!!! If you need support, post the topmost build error, and the call stack if
relevant.

------- Comment #6 From Andrej Kacian (RETIRED) 2007-01-13 16:08:57 0000 -------
Created an attachment (id=106817) [details]
mod_auth_kerb-5.0-axps1.patch-25129.out

------- Comment #7 From Raphael Marichez 2007-01-13 20:22:21 0000 -------
Ticho, please sync again, the last commit by phreak is not OK 

------- Comment #8 From Andrej Kacian (RETIRED) 2007-01-13 22:48:26 0000 -------
Created an attachment (id=106864) [details]
merge log

Synced, but compilation fails. Merge log attached.

------- Comment #9 From Raphael Marichez 2007-01-14 00:47:58 0000 -------
Thx ticho.

phreak, your turn :)

------- Comment #10 From Torsten Veller 2007-01-15 07:08:33 0000 -------
Ticho was happy and asked me to stabilize it.

------- Comment #11 From Raphael Marichez 2007-01-15 23:38:53 0000 -------
Perfet, thanks.

Time to vote for a GLSA.

Despite of the overflow, mitre.org only mentions a DoS. I really hesitate.

------- Comment #12 From Matthias Geerdsen 2007-01-17 13:48:30 0000 -------
hard to decide here...
but I tend to vote yes

------- Comment #13 From Wolf Giesen (RETIRED) 2007-01-17 13:55:04 0000 -------
The thing is that if you use kerberos, chances are good that it is
mission-critical. Hence a "yes" from me.

------- Comment #14 From Raphael Marichez 2007-01-17 22:33:31 0000 -------
Go

------- Comment #15 From Raphael Marichez 2007-01-23 00:22:48 0000 -------
GLSA 200601-14, thanks everybody.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug