Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 181179
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Icebird2000 <icebird2000@gmx.net>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 181179 depends on: Show dependency tree
Bug 181179 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-06-07 08:58 0000
+++ This bug was initially created as a clone of Bug #173368 +++

>>> quotation <<<
4. Additional information
An unrelated CVE-2007-2026 DoS vulnerability of a file(1) utility
linked with a POSIX regex(3) library on Linux systems (but not *BSD
systems) is still unresolved in file-4.21, because the offending
two lines in a file 'magic' were not removed by mistake, even though
their correct replacements were added.

The following two lines from a 'magic' file that comes with file(1)
version 4.21 need to be manually removed:

100 regex/c =^\\s*call\\s+rxfuncadd.*sysloadfu OS/2 REXX batch file text
100 regex/c =^\\s*say\ ['"] OS/2 REXX batch file text

>>> quotation <<<


Actual Results:  
can fix with the patch of file-4.20

------- Comment #1 From Sune Kloppenborg Jeppesen 2007-06-07 11:45:48 0000 -------

*** This bug has been marked as a duplicate of bug 174217 ***

------- Comment #2 From Icebird2000 2007-06-07 11:55:11 0000 -------
(In reply to comment #1)
> 
> *** This bug has been marked as a duplicate of bug 174217 ***
> 

Point 4 in the linked advisory (CVE-2007-2026) is not fixed with 4.21. 
this bugreport is for version >>>>4.21<<<< not 4.20 and the bug from 4.20 is
also in 4.21, so please fix it.

------- Comment #3 From Sune Kloppenborg Jeppesen 2007-06-07 12:36:29 0000 -------
Sorry, didn't notice that it was not properly fixed in 4.21. Handling it on the
original bug #174217.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug