First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 230045
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 230045 depends on: Show dependency tree
Bug 230045 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-06-29 16:01 0000
Issue 1:
http://marc.info/?l=bugtraq&m=121449329530282&w=4

Issues 2 and 3:
http://crisp.cs.du.edu/?q=ca2007-1

------- Comment #1 From Olivier Crete 2008-07-02 04:19:20 0000 -------
err .. 2007-01 is for version 2.0.0.....

2.4.3 should be released soon according to upstream

------- Comment #2 From Robert Buchholz 2008-07-02 07:53:42 0000 -------
That's correct, it has been reported for 2.0.0 -- but looking at the code in
2.4.2, the patches linked in the advisory never made it in. Was this fixed at
another place?

------- Comment #3 From Olivier Crete 2008-07-02 14:19:42 0000 -------
2955 seems fixed by 2.4.3 .. 2956 and 2957 don't seem to be

------- Comment #4 From Robert Buchholz 2008-07-02 20:01:20 0000 -------
Arches, please test and mark stable:
=net-im/pidgin-2.4.3
Target keywords : "alpha amd64 hppa ia64 ppc sparc x86"

------- Comment #5 From Olivier Crete 2008-07-02 20:02:48 0000 -------
*** Bug 229099 has been marked as a duplicate of this bug. ***

------- Comment #6 From Ferris McCormick 2008-07-02 20:46:31 0000 -------
On sparc at least, I'm not sure this installs the pidgin executable unless you
have USE=gtk?  Can anyone confirm?  Is this intentional?

------- Comment #7 From Olivier Crete 2008-07-02 20:54:06 0000 -------
This is intentional, if you have neither the gtk nor ncurses use flags, then
you only get libpurple (which is used by telepathy-haze for example).

------- Comment #8 From Ferris McCormick 2008-07-02 21:22:53 0000 -------
Thanks for the information (although it seems strange.  Does it warn the user
in this case (USE='-ncurses gtk')?  If so, I didn't see it; if not, it might be
worth considering.)  I am used to having USE=tk work as an alternative to
USE=gtk.

Sparc stable.

------- Comment #9 From Thomas Anderson (tanderson) 2008-07-02 21:26:54 0000 -------
amd64 stable

------- Comment #10 From Olivier Crete 2008-07-02 21:35:53 0000 -------
Err.. USE=tk is completely different from USE=gtk, but I agree its probably a
good idea to add a warning

------- Comment #11 From Olivier Crete 2008-07-02 21:36:32 0000 -------
actually, there is already an elog message when you do that..

------- Comment #12 From Christian Faulhammer 2008-07-03 12:38:52 0000 -------
x86 stable, this is good for people using ICQ, too.

------- Comment #13 From DEMAINE Benoît-Pierre, aka DoubleHP 2008-07-03 19:30:27 0000 -------
net-im/pidgin-2.4.3 is already stable (x86) in portage on mirors :) Every one
can update :) (I hope this will fix MSN and ICQ problems)

------- Comment #14 From Robert Buchholz 2008-07-03 20:33:16 0000 -------
(In reply to comment #3)
> 2955 seems fixed by 2.4.3

Did you research the code? I could find no indication in the ChangeLog.

------- Comment #15 From Olivier Crete 2008-07-03 20:51:35 0000 -------
I believe these are the two relevant commits to 2955 in 2.4.3:
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/709ec9c29e9d76eebbded25061107ef0a2a2b148
http://developer.pidgin.im/viewmtn/revision/diff/e09d33c61a6e5a59bfc3a52a4370aadf0a90f254/with/c3831c9181f4f61b747321240086ee79e4a08fd8

But I see nothign in their tree about the two other CVEs... Did I mentin that
viewmtn sucks balls?

------- Comment #16 From DEMAINE Benoît-Pierre, aka DoubleHP 2008-07-03 23:29:33 0000 -------
I just emerged 2.4.3 ... I dont know if it fixes the mentioned security issue,
but MSN now works again. I mean: this new version is now compatible with the
update of most servers.

------- Comment #17 From Jeroen Roovers 2008-07-04 00:02:34 0000 -------
Stable for HPPA.

------- Comment #18 From Raúl Porcel 2008-07-04 15:25:04 0000 -------
alpha/ia64 stable

------- Comment #19 From Tobias Scherbaum 2008-07-05 11:54:24 0000 -------
ppc stable

------- Comment #20 From Pierre-Yves Rofes 2008-07-06 18:20:23 0000 -------
glsa request filed.

------- Comment #21 From Robert Buchholz 2008-07-06 21:51:53 0000 -------
As pointed out in [1], the update fixes another issue, CVE-2008-2927 -- and not
the MSN filename. So back to [ebuild].

[1] http://article.gmane.org/gmane.comp.security.oss.general/618

------- Comment #22 From Robert Buchholz 2008-07-30 18:41:05 0000 -------
upstream bug for CVE-2008-2955
http://developer.pidgin.im/ticket/6246

------- Comment #23 From Pierre-Yves Rofes 2008-09-25 21:33:49 0000 -------
(In reply to comment #22)
> upstream bug for CVE-2008-2955
> http://developer.pidgin.im/ticket/6246
> 

It's fixed upstream... so where are we now? Is this fix included in 2.5.1?

------- Comment #24 From Robert Buchholz 2008-11-27 17:17:25 0000 -------
http://www.pidgin.im/news/security/ states:

CVE-2008-2957 was fixed in 2.5.0
CVE-2008-2955 was fixed in 2.4.3
CVE-2008-2927 was fixed in 2.4.3

It seems upstream does not consider CVE-2008-2956 an issue, as they have no bug
report or similar. Since this would only lead to a client-side DoS, we might
want to ignore it as well.

------- Comment #25 From Pierre-Yves Rofes 2009-01-20 22:04:12 0000 -------
GLSA 200901-13, sorry for the delay.

First Last Prev Next    No search results available      Search page      Enter new bug