First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 208999
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
ghostscript-8.60-CVE-2008-0411.diff ghostscript-8.60-CVE-2008-0411.diff patch Robert Buchholz 2008-02-14 02:28 0000 415 bytes Details | Diff
ghostscript-gnu-8.60.0-r1.ebuild.patch ghostscript-gnu-8.60.0-r1.ebuild.patch patch Peter Volkov 2008-02-25 07:32 0000 435 bytes Details | Diff
ghostscript-esp-8.15.4.ebuild.patch ghostscript-esp-8.15.4.ebuild.patch patch Peter Volkov 2008-02-25 08:57 0000 2.17 KB Details | Diff
ghostscript-gpl-8.61-r2.ebuild.patch ghostscript-gpl-8.61-r2.ebuild.patch patch Peter Volkov 2008-02-25 09:00 0000 520 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 208999 depends on: Show dependency tree
Bug 208999 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-05 13:58 0000
Stack-based buffer overflow in the zseticcspace() function in zicc.c, will
result in arbitrary code execution.

Currently under embargo, awaiting upstream patch. The $URL is private.

------- Comment #1 From Robert Buchholz 2008-02-14 02:28:20 0000 -------
Tom and Stefan, can you please create an ebuild with the patch applied and
attach it to this bug. Do not commit anything to CVS yet as long as this bug is
under embargo.

------- Comment #2 From Robert Buchholz 2008-02-14 02:28:50 0000 -------
Created an attachment (id=143467) [details]
ghostscript-8.60-CVE-2008-0411.diff

------- Comment #3 From Robert Buchholz 2008-02-24 11:17:28 0000 -------
Tom and Stefan, can you please prepare an ebuild so we can test this before
Feb. 27?

------- Comment #4 From Peter Volkov 2008-02-25 07:32:37 0000 -------
Created an attachment (id=144554) [details]
ghostscript-gnu-8.60.0-r1.ebuild.patch

I'll attach patch's for maintainer and others review. This one is for
ghostscript-gnu. Other ghostscript packages will follow as soon as I test
them...

------- Comment #5 From Peter Volkov 2008-02-25 08:57:02 0000 -------
Created an attachment (id=144560) [details]
ghostscript-esp-8.15.4.ebuild.patch

Patch for ghostscript-esp. Includes lot's of quotations fixes.

------- Comment #6 From Peter Volkov 2008-02-25 09:00:50 0000 -------
Created an attachment (id=144561) [details]
ghostscript-gpl-8.61-r2.ebuild.patch

And this is patch for ghostscript-gpl. But note during commit patch itself
should go into  ghostscript-gpl-8.61-patchset-4.tar.bz2. So this patch is for
testing purposes only.

------- Comment #7 From Robert Buchholz 2008-02-25 16:05:59 0000 -------
Arch Security Liaisons, please test the attached ebuilds and report stable on
this bug.

=app-text/ghostscript-esp-8.15.4-r1
Target keywords : "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 release s390
sh sparc x86"

=app-text/ghostscript-gnu-8.60.0-r2
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 release sh sparc x86"

=app-text/ghostscript-gpl-8.61-r3
Target keywords : "ppc64 release"


CC'ing current Liaisons:
   alpha : ferdy
   amd64 : welp
    hppa : jer
     ppc : dertobi123
   ppc64 : corsair
 release : pva
   sparc : fmccor
     x86 : opfer

------- Comment #8 From Robert Buchholz 2008-02-25 16:06:53 0000 -------
Oh, and thanks Peter for preparing the ebuilds and doing some QA on the
existing ones.

------- Comment #9 From Jeroen Roovers 2008-02-25 17:47:34 0000 -------
Both are good for HPPA.

------- Comment #10 From Christian Faulhammer 2008-02-25 17:51:23 0000 -------
(In reply to comment #7)
> Arch Security Liaisons, please test the attached ebuilds and report stable on
> this bug.

There is something wrong with the keywords:
> =app-text/ghostscript-gpl-8.61-r3
> Target keywords : "ppc64 release"

 Especially this one.

------- Comment #11 From Jeroen Roovers 2008-02-25 17:55:49 0000 -------
(In reply to comment #10)
> (In reply to comment #7)
> > Arch Security Liaisons, please test the attached ebuilds and report stable on
> > this bug.
> 
> There is something wrong with the keywords:
> > =app-text/ghostscript-gpl-8.61-r3
> > Target keywords : "ppc64 release"
> 
>  Especially this one.

Not just that - AFAIK ghostscript-esp is getting dropped somewhere in the
future and this bug doesn't have an attachment that patches a ghostscript-esp
ebuild.

Also odd is that patch to a few ebuilds were posted instead of the new ebuilds
themselves as is common practice.

------- Comment #12 From Christian Faulhammer 2008-02-25 17:58:24 0000 -------
(In reply to comment #11)
> (In reply to comment #10)
> > (In reply to comment #7)
> > > Arch Security Liaisons, please test the attached ebuilds and report stable on
> > > this bug.
> > 
> > There is something wrong with the keywords:
> > > =app-text/ghostscript-gpl-8.61-r3
> > > Target keywords : "ppc64 release"
> > 
> >  Especially this one.
> 
> Not just that - AFAIK ghostscript-esp is getting dropped somewhere in the
> future and this bug doesn't have an attachment that patches a ghostscript-esp
> ebuild.

 It does.  See comment #5.

> Also odd is that patch to a few ebuilds were posted instead of the new ebuilds
> themselves as is common practice.

 Not that bad.

------- Comment #13 From Robert Buchholz 2008-02-25 18:03:07 0000 -------
(In reply to comment #10)
> There is something wrong with the keywords:

Yes, sorry. I mixed up gpl and gnu.


=app-text/ghostscript-esp-8.15.4-r1
Target keywords : "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 release s390
sh sparc x86"

=app-text/ghostscript-gnu-8.60.0-r2
Target keywords : "ppc64 release"

=app-text/ghostscript-gpl-8.61-r3
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 release sh sparc x86"

------- Comment #14 From Christian Faulhammer 2008-02-25 18:09:57 0000 -------
Ok...-gpl and -esp fine on x86, they survived my stress test with different
things on a really huge PostScript file.

------- Comment #15 From Jeroen Roovers 2008-02-25 18:15:39 0000 -------
(In reply to comment #12)
>  It does.  See comment #5.

Ow, missed that. Sorry.

> > Also odd is that patch to a few ebuilds were posted instead of the new ebuilds
> > themselves as is common practice.
> 
>  Not that bad.

It's bad when you require seven people to download and apply three patches
individually - it's one more step to perform in testing each of the ebuilds.

------- Comment #16 From Peter Volkov 2008-02-25 18:28:03 0000 -------
Jeroen I didn't knew that and will do next time. Right now I've downloaded 5
patches for shorewall* packages and believe me - patches are not so hard to use
;) Just 2-3 additional commands but they worth it as patch greatly simplify
review. If that's necessary I can attach full ebuilds now.

------- Comment #17 From Jeroen Roovers 2008-02-26 04:22:32 0000 -------
ghostscript-esp is good for HPPA too.

------- Comment #18 From Tobias Scherbaum 2008-02-26 19:55:47 0000 -------
looks good on ppc ...

------- Comment #19 From Markus Rothe 2008-02-28 08:33:09 0000 -------
looks good on ppc64, too.

------- Comment #20 From Ferris McCormick 2008-02-28 21:13:30 0000 -------
ghostscript-gpl-8.61.r2 is good on sparc; the others look good on sparc.  I
also thought ghostscript-esp was either dying or dead, but it does look good. 
Why are we keeping it around?

------- Comment #21 From Peter Weller 2008-02-28 21:51:44 0000 -------
Looks good for amd64 too.

------- Comment #22 From Robert Buchholz 2008-02-29 08:54:28 0000 -------
This is public now. Peter/Printing, can you commit this to the tree with the
stable keywords mentioned here. I can re-cc the missing arches. 

------- Comment #23 From Peter Volkov 2008-02-29 12:22:14 0000 -------
Commited in the tree.

Target keywords left:
=app-text/ghostscript-esp-8.15.4-r1: "release, alpha, arm, ia64, m68k, mips,
s390, sh"
=app-text/ghostscript-gpl-8.61-r3: "release, alpha, arm, ia64, m68k, sh"

Seems that the only reason to keep app-text/ghostscript-esp in the tree is that
mips, s390 and sh still have not keyworded/stabilized
app-text/ghostscript-{gpl,gnu}.

------- Comment #24 From Raúl Porcel 2008-03-01 20:21:17 0000 -------
alpha/ia64 stable, Robert, i think i told you to cc me on restricted bugs, i
hate you now! :P

------- Comment #25 From Ryan Hill 2008-03-01 22:18:18 0000 -------
mips is going all ~arch.

------- Comment #26 From Peter Volkov 2008-03-02 08:32:11 0000 -------
Fixed in release snapshot.

------- Comment #27 From Sune Kloppenborg Jeppesen 2008-03-02 15:26:05 0000 -------
Seems ready for GLSA.

------- Comment #28 From Timo Gurr 2008-03-04 21:08:21 0000 -------
Just a note: I committed ghostscript-gpl-8.62 to the tree a few minutes ago
which had the fix applied upstream.

------- Comment #29 From Pierre-Yves Rofes 2008-03-08 18:30:41 0000 -------
GLSA 200803-14

First Last Prev Next    No search results available      Search page      Enter new bug