Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 178575
Alias:
Product:
Component:
Status: ASSIGNED
Resolution:
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Diego E. 'Flameeyes' Pettenò <flameeyes@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 178575 depends on: Show dependency tree
Bug 178575 blocks: 177842 179162 215614

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-05-14 21:41 0000
As per summary, with the disclosure of OpenJDK sources we can confirm that the
libpng copy on it is not patched to fix the vulnerability in summary
(CVE-2006-5793), which makes its splashscreen support vulnerable to that issue.

------- Comment #1 From Sune Kloppenborg Jeppesen 2007-05-15 06:46:10 0000 -------
java please advise and bump as necessary.

------- Comment #2 From Vlastimil Babka (Caster) 2007-05-15 07:48:13 0000 -------
Cannot bump, upstream has to confirm the bug first (Diego please post upstream
URL when they accept it) and hopefully fix it. How do you know it affects also
1.6? OpenJDK is 1.7. What about 1.5 or even 1.4? :)

------- Comment #3 From Diego E. 'Flameeyes' Pettenò 2007-05-15 10:33:46 0000 -------
From a reply of Phil Race on awt-dev:

> libgif and libpng are only in JDK since 1.6, and the same is
> true for splashscreen's use of openjdk so there's not too
> much history there to worry about yet.

The code of libpng released with OpenJDK is not patched, so I don't think they
patched the 1.6 release either, they didn't seem to know about it to begin
with.

------- Comment #4 From Vlastimil Babka (Caster) 2007-05-15 19:40:34 0000 -------
Hm and just recently we asked for the JRE to go stable, and x86 already did it.
But if I understand correctly, it will just crash the JVM when starting some
app with malicious splash screen? And no execution of code?

------- Comment #5 From Martin Capitanio 2007-05-17 06:58:44 0000 -------
(In reply to comment #4)
> app with malicious splash screen? And no execution of code?

http://scary.beasts.org/security/CESA-2006-004.html

Fixed in: JDK 1.5.0_11-b03 and JDK 1.6.0_01-b06.

gentoo>java -version
1.6.0-b105 ???
1.5.0_11-b03

_Reported date: October 2006._
Advisory release date: May 15th 2007.

"This, on Linux, causes the image parsing thread to hang whilst trying to read
from /dev/tty."

------- Comment #6 From Vlastimil Babka (Caster) 2007-05-17 09:43:12 0000 -------
(In reply to comment #5)
> (In reply to comment #4)
> > app with malicious splash screen? And no execution of code?
> 
> http://scary.beasts.org/security/CESA-2006-004.html

That's different issue, I've created bug 178851 for it, thanks for reporting!

------- Comment #7 From Diego E. 'Flameeyes' Pettenò 2007-05-18 16:39:51 0000 -------
The bug report was accepted by Sun, but it will take a day or two before being
visible at the URL I just added to the report.

------- Comment #8 From Sune Kloppenborg Jeppesen 2007-05-19 22:32:33 0000 -------
Handling 179162 on bug #179162.

------- Comment #9 From Petteri Räty 2007-06-02 16:21:27 0000 -------
sun released u1 so x86 please mark sun-jre-bin-1.6.0.1 stable

------- Comment #10 From Petteri Räty 2007-06-02 16:32:43 0000 -------
(In reply to comment #9)
> sun released u1 so x86 please mark sun-jre-bin-1.6.0.1 stable
> 

Take that back. This issue is not fixed with u1.

------- Comment #11 From Sune Kloppenborg Jeppesen 2007-07-01 02:17:21 0000 -------
Petteri, any news on this one?

------- Comment #12 From Petteri Räty 2007-07-01 08:25:36 0000 -------
(In reply to comment #11)
> Petteri, any news on this one?
> 

It will take a while before Sun is able to react to this. Hopefully in time for
u2 but I am betting u3.

------- Comment #13 From Sune Kloppenborg Jeppesen 2007-08-21 06:16:01 0000 -------
Petteri, any news on this one?

------- Comment #14 From Sune Kloppenborg Jeppesen 2007-11-07 19:49:20 0000 -------
Petteri, any news on this one?

------- Comment #15 From Vlastimil Babka (Caster) 2007-11-08 06:19:40 0000 -------
The upstream bug is still not public. We should be asking Diego if he got any
response...

------- Comment #16 From Diego E. 'Flameeyes' Pettenò 2007-11-08 10:54:47 0000 -------
The bug is private to me too, I had no direct response though.

------- Comment #17 From Robert Buchholz 2008-04-17 23:47:52 0000 -------
"This bug is not available." -- is there any update available here? If not, we
should contact the Sun people.

------- Comment #18 From Matthias Geerdsen 2008-07-07 18:46:13 0000 -------
Any news available here? Any comments from upstream?

------- Comment #19 From Matti Bickel 2008-12-26 23:03:40 0000 -------
A year and half old bug and still no upstream fix? What's going on here?

------- Comment #20 From Andrew John Hughes 2008-12-31 11:18:15 0000 -------
Note that this doesn't affect icedtea6 as it fixes Sun's build system to link
against the system libpng.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug