First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 201292
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Christian Hoffmann <hoffie@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 201292 depends on: 201747 Show dependency tree
Bug 201292 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-12-04 22:36 0000
Upstream changelog for version 4.4.2 lists:
  # Allocate copy of passed cliend id, program name and working directory in
    session management, in case the application frees the data.
  # Properly deal with %-starting 'field codes' in commands from .desktop
files.

Not sure if those are vulnerabilities at all, I'm not that familiar with XFCE
code. Better safe than sorry, I'd say. ;)
Don't have any further details here either.

------- Comment #1 From Christian Hoffmann 2007-12-04 22:53:13 0000 -------
Bleh, sorry for the bug spam. Getting the summary right is hard. ;)
It was wrong before, should be better now, but I'm still not sure.

------- Comment #2 From Lubomir Rintel 2007-12-05 20:06:43 0000 -------
First issue, libxfce4gui:

4.4: http://svn.xfce.org/index.cgi/xfce4/revision?rev=25554
trunk: http://svn.xfce.org/index.cgi/xfce4/revision?rev=25555

------- Comment #3 From Lubomir Rintel 2007-12-05 20:12:31 0000 -------
The "%" one:

4.4: http://svn.xfce.org/index.cgi/xfce4/revision/?rev=25677

------- Comment #4 From Pierre-Yves Rofes 2007-12-08 23:45:44 0000 -------
xfce: ok for 4.4.2 going stable?

------- Comment #5 From Samuli Suominen 2007-12-09 09:02:49 0000 -------
(In reply to comment #4)
> xfce: ok for 4.4.2 going stable?
> 

bug 201747

------- Comment #6 From Robert Buchholz 2007-12-22 13:21:58 0000 -------
All but MIPS stable on bug 201747, setting GLSA.

------- Comment #7 From Robert Buchholz 2007-12-22 15:44:29 0000 -------
The % issue is not a security problem, as it only means that %U and other
strings do not get removed from Exec calls in .desktop files.

------- Comment #8 From Robert Buchholz 2008-01-08 22:10:39 0000 -------
CVE-2007-6532 was assigned to the double free.

------- Comment #9 From Robert Buchholz 2008-01-09 23:31:20 0000 -------
GLSA 200801-06

------- Comment #10 From Josh Saddler 2008-01-10 06:22:42 0000 -------
(In reply to comment #9)
> GLSA 200801-06
> 

. . . I know the GLEP was already sent and posted to the forums, but you should
be aware that I finally removed the Upgrading section last month, as 4.2 was
removed from Portage a looooooong time ago. Even 4.4 and 4.4.1 have been
removed from the tree. Anyway, the upgrade path outlined in the guide no longer
exists; drac had been doing many ebuild changes so that it would have required
different procedures.

Users will have to visit CVS[1] to see the last version of the guide with that
chapter.

[1]
http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/doc/en/xfce-config.xml?rev=1.14&view=markup

------- Comment #11 From Robert Buchholz 2008-01-10 11:09:26 0000 -------
Thanks for pointing that out, I removed the reference.

First Last Prev Next    No search results available      Search page      Enter new bug