First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 177512
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 177512 depends on: Show dependency tree
Bug 177512 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-05-07 16:13 0000
Untrusted search path vulnerability in the add_filename_to_string function in
intl/gettext/loadmsgcat.c for Elinks 0.11.1 adds "../po" to the search path for
.po files, which might allow local users to cause Elinks to use an untrusted
gettext message catalog, which can be leveraged to conduct format string
attacks.

------- Comment #1 From Jakub Moc (RETIRED) 2007-05-09 11:48:02 0000 -------
*** Bug 177777 has been marked as a duplicate of this bug. ***

------- Comment #2 From Sune Kloppenborg Jeppesen 2007-05-19 22:41:17 0000 -------
spock please advise.

------- Comment #3 From Michal Januszewski 2007-05-21 17:24:02 0000 -------
This is now fixed in CVS thanks to a patch pulled from the elinks GIT tree.

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-05-21 18:30:57 0000 -------
Thx Micheal. 

Could you make a revbump of the latest stable so users can use glsa-check to
upgrade and arches have a chance to test?

------- Comment #5 From Sune Kloppenborg Jeppesen 2007-05-21 18:46:15 0000 -------
Woops didn't mean to CC arches already. Sorry for the noise.

------- Comment #6 From Michal Januszewski 2007-05-21 21:00:09 0000 -------
Done, 0.11.2-r1 is in CVS now.

------- Comment #7 From Pierre-Yves Rofes 2007-05-31 09:44:03 0000 -------
Jaervosz, seems it's ok for calling arches this time :)

------- Comment #8 From Sune Kloppenborg Jeppesen 2007-06-01 05:54:27 0000 -------
Thx for the reminder:-)

Arches please test and mark stable. Target keywords are:

elinks-0.11.2-r1.ebuild:KEYWORDS="alpha amd64 hppa mips ppc ppc64 sparc x86
~x86-fbsd"

------- Comment #9 From Raúl Porcel 2007-06-01 12:36:08 0000 -------
alpha/x86 stable

------- Comment #10 From Peter Weller 2007-06-01 12:45:43 0000 -------
amd64 done

------- Comment #11 From Gustavo Zacarias (RETIRED) 2007-06-01 13:27:11 0000 -------
sparc stable.

------- Comment #12 From Brent Baude 2007-06-01 14:49:42 0000 -------
ppc64 stable

------- Comment #13 From Jeroen Roovers 2007-06-01 16:12:19 0000 -------
Stable for HPPA.

------- Comment #14 From René Nussbaumer 2007-06-02 20:09:19 0000 -------
stable on ppc

------- Comment #15 From Raphael Marichez 2007-06-07 21:30:56 0000 -------
GLS 200706-03, thanks everybody!

mips don't forget to mark stable to befenit from the glsa

------- Comment #16 From Joshua Kinard 2007-06-28 06:22:11 0000 -------
mips stable.

First Last Prev Next    No search results available      Search page      Enter new bug