First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 263023
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 263023 depends on: Show dependency tree
Bug 263023 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2009-03-19 12:32 0000
** Please note that this issue is confidential and no information should be
disclosed until it is made public, see "Whiteboard" for a date **

James Peach of Apple discovered a stack-based buffer overflow in cscope's
handling of long file system paths. Processing a maliciously crafted source
file may lead to an unexpected application termination or arbitrary code
execution.

------- Comment #1 From Robert Buchholz 2009-03-19 12:34:47 0000 -------
Apple provided us with a reproducer for the issue.
A patch is being discussed upstream.

------- Comment #2 From Robert Buchholz 2009-05-02 09:48:26 0000 -------
This is now public, please bump the version in tree.

------- Comment #3 From Ulrich Müller 2009-05-02 10:04:35 0000 -------
Bumped to 15.7a. Arch teams, please stabilise.

------- Comment #4 From Jeroen Roovers 2009-05-02 14:15:42 0000 -------
Stable for HPPA.

------- Comment #5 From Tobias Klausmann 2009-05-03 12:18:29 0000 -------
Stable on alpha.

------- Comment #6 From Markus Meier 2009-05-03 12:35:25 0000 -------
amd64/x86 stable

------- Comment #7 From Brent Baude 2009-05-03 12:41:52 0000 -------
ppc done

------- Comment #8 From Brent Baude 2009-05-03 12:47:22 0000 -------
ppc64 done

------- Comment #9 From Tiago Cunha 2009-05-03 17:59:55 0000 -------
sparc stable

------- Comment #10 From Tobias Heinlein 2009-05-03 18:51:34 0000 -------
GLSA request filed.

------- Comment #11 From Raúl Porcel 2009-05-06 15:22:01 0000 -------
arm/ia64/m68k/s390/sh stable

------- Comment #12 From Alex Legler 2009-05-06 19:06:59 0000 -------
CVE-2009-0148 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0148):
  Multiple buffer overflows in Cscope before 15.7a allow remote
  attackers to execute arbitrary code via (1) long pathnames, (2) long
  source-code strings, and other vectors.

------- Comment #13 From Alex Legler 2009-05-15 09:18:46 0000 -------
CVE-2009-1577 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1577):
  Multiple stack-based buffer overflows in the putstring function in
  find.c in Cscope before 15.6 allow user-assisted remote attackers to
  execute arbitrary code via a long (1) function name or (2) symbol in
  a source-code file.

------- Comment #14 From Pierre-Yves Rofes 2009-05-24 13:06:29 0000 -------
GLSA 200905-02

First Last Prev Next    No search results available      Search page      Enter new bug