First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 160793
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Executioner <keith@email.arizona.edu>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
centericq-4.21.0-livejrnl-buffoverflow-fix.diff Live journal buffer overflow patch patch Mike Pagano 2007-01-19 15:41 0000 1.07 KB Details | Diff
centericq-4.21.0-jabber-segfault-fix.diff jabber segmentation fault fix patch Mike Pagano 2007-01-19 15:42 0000 827 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 160793 depends on: Show dependency tree
Bug 160793 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-01-07 22:46 0000
CenterICQ contains support for LiveJournal (http://www.livejournal.com/),
  such as posting to your own blog, reading other blogs' RSS feeds, and
other
  community-related functions, such as showing whether a user has added or
  removed your own users to/from the friend list, all via a unified HTTP
  interface provided by LiveJournal. The latter functionality is vulnerable
  to a buffer overflow and possible remote code execution.



Reproducible: Didn't try

------- Comment #1 From Executioner 2007-01-07 22:47:55 0000 -------
We are at centericq-4.21.0-r2, are we still vulnerable?

------- Comment #2 From Stefan Cornelius (RETIRED) 2007-01-08 18:23:14 0000 -------
Well, it seems like our source looks like the affected source in the advisory,
so I guess we failed to dodge the bullet here and are vulnerable (i havent
checked the actual exploitability, but seems reasonable enough)

------- Comment #3 From Simon Stelling (RETIRED) 2007-01-08 21:22:19 0000 -------
"Executioner", I see you CCd me on this bug, but I don't know why. Could you
explain please? :)

------- Comment #4 From Stefan Cornelius (RETIRED) 2007-01-08 22:27:56 0000 -------
oh, thats what i get for not checking the maintainer! wschlich, pls have a
look, thx

------- Comment #5 From Wolfram Schlich 2007-01-09 00:41:57 0000 -------
I am not the maintainer anymore :)
See bug #81422, bug #88640, bug #116962, bug #131426, bug #138154, bug #138740
and net-im/centericq ChangeLog entry from 14 Jul 2006.
Sorry.

------- Comment #6 From Sune Kloppenborg Jeppesen 2007-01-09 08:35:44 0000 -------
-dev mailed. Unless someone is willing to take over this package I propose a
mask.

------- Comment #7 From Olivier Crete 2007-01-09 13:23:32 0000 -------
seems like centericq is unmaintained upstream...

------- Comment #8 From Olivier Crete 2007-01-13 20:39:17 0000 -------
I masked it (for net-im).

------- Comment #9 From Simon Stelling (RETIRED) 2007-01-14 02:15:20 0000 -------
*** Bug 117358 has been marked as a duplicate of this bug. ***

------- Comment #10 From Sune Kloppenborg Jeppesen 2007-01-14 07:57:54 0000 -------
If C2 rating is correct this one needs a mask GLSA.

------- Comment #11 From Raphael Marichez 2007-01-14 18:03:10 0000 -------
(In reply to comment #10)
> If C2 rating is correct this one needs a mask GLSA.
> 

it seems so. GLSA request filled.

------- Comment #12 From Mike Pagano 2007-01-19 15:37:59 0000 -------
Not sure if the point is moot with this being masked for removal but here's a
mailing list posting with links to a patch from Debian for the buffer overflow
and an additional bug fix.

http://article.gmane.org/gmane.network.centericq/4252

------- Comment #13 From Mike Pagano 2007-01-19 15:41:49 0000 -------
Created an attachment (id=107457) [details]
Live journal buffer overflow patch

------- Comment #14 From Mike Pagano 2007-01-19 15:42:33 0000 -------
Created an attachment (id=107458) [details]
jabber segmentation fault fix

------- Comment #15 From Raphael Marichez 2007-01-22 11:56:54 0000 -------
(In reply to comment #12)
> Not sure if the point is moot with this being masked for removal but here's a
> mailing list posting with links to a patch from Debian for the buffer overflow
> and an additional bug fix.
> 
> http://article.gmane.org/gmane.network.centericq/4252
> 

but there was no maintainer having answered to the gentoo-dev@ call :(

Olivier, want to have a look?

------- Comment #16 From Jakub Moc (RETIRED) 2007-01-22 16:40:33 0000 -------
(In reply to Comment #12:

You know, we have lots of patches attached to the bugs quoted above, but with
completely unresponsive upstream they are basically useless. Noone's willing to
become upstream for this thing and waste more time on this.

------- Comment #17 From Matthias Geerdsen 2007-01-24 20:00:40 0000 -------
mask GLSA 200701-20

------- Comment #18 From Honza 2007-01-27 11:21:16 0000 -------
Is there any other text-based ICQ client ?

------- Comment #19 From Olivier Crete 2007-01-27 15:39:32 0000 -------
there is gaim-text and naim at least

------- Comment #20 From Daniel Gebhardt 2007-02-23 09:58:34 0000 -------
(In reply to comment #16)

> Noone's willing to become upstream for this thing 

Digging around a little I found some people are trying to keep centericq alive.

http://thread.gmane.org/gmane.network.centericq/4294

The repository of the fork is online here: 
http://repo.or.cz/w/centerim.git

So maybe its possible to keep center(icq/im) in portage somehow

------- Comment #21 From Kai Sommer 2007-03-21 14:11:19 0000 -------
(In reply to comment #20)
> Digging around a little I found some people are trying to keep centericq
> alive.
> 
> http://thread.gmane.org/gmane.network.centericq/4294
> 
> [...]
> 
> So maybe its possible to keep center(icq/im) in portage somehow
Dear CenterICQ-users,
the future of CenterICQ has begone and is named CenterIM! :)
Please look at the Forums under
http://forums.gentoo.org/viewtopic-t-548358.html and in the Bugtracker at
https://bugs.gentoo.org/show_bug.cgi?id=171682 for further informations.

please look at the "new" CenterICQ-fork: CenterIM.
The first CenterIM-ebuild (4.22.0) is available

------- Comment #22 From Fred Thiele 2007-07-05 17:25:57 0000 -------
Whats up? Centericq is masked, full of void* to int cast errors (fixed them),
still lacks of jabber support for amd64. And now I'm reading about centerim,
which isn't in the portage tree. Can someone tell me whats up?

------- Comment #23 From Olivier Crete 2007-07-05 17:36:26 0000 -------
CenterICQ will at some point in the near future be remove from the tree. And
there is no gentoo developer who has decided to add centerim to the tree for
now. maybe I'll do it at some point

------- Comment #24 From Christian Faulhammer 2007-09-08 22:43:32 0000 -------
(In reply to comment #23)
> CenterICQ will at some point in the near future be remove from the tree. And
> there is no gentoo developer who has decided to add centerim to the tree for
> now. maybe I'll do it at some point

centerim is in the tree, so please remove centericq.

------- Comment #25 From Olivier Crete 2007-09-11 02:22:27 0000 -------
Its now out of the tree. You may want to amend the GLSA to reflect that and
also suggest users to use finch (from the pidgin package with the ncurses use
flag) or centerim.

------- Comment #26 From Robert Buchholz 2007-12-17 13:10:14 0000 -------
Gone from the tree since September. Thanks!

First Last Prev Next    No search results available      Search page      Enter new bug