Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 264598 (CVE-2009-1284) - <app-text/texlive-core-2008-r7: bibtex invalid reads/writes when parsing big *.bib file (CVE-2009-1284)
Summary: <app-text/texlive-core-2008-r7: bibtex invalid reads/writes when parsing big ...
Status: RESOLVED FIXED
Alias: CVE-2009-1284
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B2 [glsa]
Keywords:
Depends on: 227443
Blocks:
  Show dependency tree
 
Reported: 2009-04-02 10:30 UTC by Robert Buchholz (RETIRED)
Modified: 2012-06-25 19:10 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-04-02 10:30:10 UTC
On Wednesday 01 April 2009, Jan Lieskovsky wrote:
> 1, bibtex invalid reads/writes when parsing big *.bib file
>           (valgrind reports suspicious behavior)
>    References:
>    http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=520920 
> (texlive-base-bin) https://bugzilla.redhat.com/show_bug.cgi?id=492136
> (tetex, texlive)
>
>    The problem is in bibtex, but looks like it is shipped
>    in various packages for various vendors.

We ship bibtex in teTeX, TeX Live and pTeX. Since pTeX is based on teTeX 2, I do not know whether it is affected. The other two products seem to be. Do we want to provide an upgrade path to teTeX, or will this be the moment for masking it?
Comment 1 Ulrich Müller gentoo-dev 2009-04-02 10:49:41 UTC
> Do we want to provide an upgrade path to teTeX,

No. See bug 227443 for its current status.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-04-02 11:04:01 UTC
Ok, adding that bug as a blocker then.
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-10 20:28:05 UTC
(In reply to comment #0)
> We ship bibtex in teTeX, TeX Live and pTeX. Since pTeX is based on teTeX 2, I
> do not know whether it is affected. The other two products seem to be. 

Confirming that bibtex 0.99c as shipped in app-text/texlive-core-2008-r4 is vulnerable.
Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-10 20:28:31 UTC
CVE-2009-1284 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1284):
  Buffer overflow in BibTeX 0.99 allows context-dependent attackers to
  cause a denial of service (memory corruption and crash) via a long
  .bib bibliography file.

Comment 5 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2009-05-30 00:46:07 UTC
treecleaner this from the tree. Do what you would like now.
Comment 6 Alexis Ballier gentoo-dev 2009-08-27 07:49:50 UTC
Karl posted a patch on the texlive ml fixing this issue; it is now applied in texlive-core-2008-r7, sorry for the delay.
Comment 7 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-27 08:17:54 UTC
Split ptex off to bug 282874 to make things a little less complicated here.

Alexis can -r7 go stable?
Comment 8 Alexis Ballier gentoo-dev 2009-08-27 08:20:20 UTC
(In reply to comment #7)
> Alexis can -r7 go stable?

Yes
Comment 9 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-27 08:27:28 UTC
Arches, please test and mark stable:
=app-text/texlive-core-2008-r7
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
Comment 10 Christian Faulhammer (RETIRED) gentoo-dev 2009-08-27 12:33:48 UTC
x86 stable
Comment 11 Steve Dibb (RETIRED) gentoo-dev 2009-08-27 21:02:29 UTC
amd64 stable
Comment 12 Raúl Porcel (RETIRED) gentoo-dev 2009-08-28 11:54:56 UTC
alpha/arm/ia64/s390/sh/sparc stabl
Comment 13 Jeroen Roovers (RETIRED) gentoo-dev 2009-08-29 12:31:07 UTC
Stable for HPPA.
Comment 14 Brent Baude (RETIRED) gentoo-dev 2009-08-30 23:36:30 UTC
ppc64 done
Comment 15 nixnut (RETIRED) gentoo-dev 2009-09-20 18:44:28 UTC
ppc stable
Comment 16 Tim Sammut (RETIRED) gentoo-dev 2010-11-20 23:28:19 UTC
GLSA request filed.
Comment 17 Johannes Huber (RETIRED) gentoo-dev 2012-05-16 07:44:37 UTC
Thank you all. <app-text/texlive-core-2008-r7 is gone from tree long time ago. Removing tex herd from cc.
Comment 18 GLSAMaker/CVETool Bot gentoo-dev 2012-06-25 19:10:31 UTC
This issue was resolved and addressed in
 GLSA 201206-28 at http://security.gentoo.org/glsa/glsa-201206-28.xml
by GLSA coordinator Stefan Behte (craig).