Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 42133
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
metamail-2.7.45-r2.ebuild ebuild using new debian patch text/plain Jason Short 2004-05-11 11:57 0000 1.01 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 42133 depends on: Show dependency tree
Bug 42133 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-02-19 03:55 0000
PROGRAM: metamail
VENDOR: Bell Communications Research, Inc. (Bellcore)
DOWNLOAD URLs: ftp://thumper.bellcore.com/pub/nsb/
               http://ftp.funet.fi/pub/unix/mail/metamail/
VULNERABLE VERSIONS: 2.2, 2.4, 2.5, 2.6, 2.7, possibly others
IMMUNE VERSIONS: 2.7 with my patch applied
REFERENCES: CAN-2004-0104 (format string bugs)
            CAN-2004-0105 (buffer overflows)

http://lists.netsys.com/pipermail/full-disclosure/2004-February/017539.html

------- Comment #1 From Kurt Lieber 2004-03-30 00:24:15 0000 -------
net-mail herd -- need a confirm/action on this.

------- Comment #2 From Kurt Lieber 2004-04-08 01:47:23 0000 -------
netmail folks?

------- Comment #3 From Thierry Carrez (RETIRED) 2004-04-13 04:59:29 0000 -------
Confirmed : format string and buffer overflows :

http://www.kb.cert.org/vuls/id/518518
http://www.kb.cert.org/vuls/id/513062

Already published advisories include 
http://www.debian.org/security/2004/dsa-449

This package is not maintained upstream. We should either drop it or apply the latest Debian package patch :
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-45woody.2.diff.gz

net-mail folks ?

-K

------- Comment #4 From Carsten Lohrke 2004-04-21 09:13:15 0000 -------
it's more than two months now - do you still read the forrester study? :)

------- Comment #5 From Thierry Carrez (RETIRED) 2004-04-29 07:16:11 0000 -------
net-mail was recently reorganized, so hopefully someone can take the metamail
package and bump the ebuild to the latest Debian patch (see comment above) ?

Thanks in advance,
-K

------- Comment #6 From Kurt Lieber 2004-05-11 08:30:44 0000 -------
masking this package for security reasons.

------- Comment #7 From Christof Schulze 2004-05-11 11:02:54 0000 -------
geez

Hardmasking this packages leaves me with a broken portage:

it constantly complains about not having metamail ready since sylpheed-claws has a dep on it.
I don't want insecure software in portage either and don't have a solution for this as for now, but something like that should not happen!
I'll try to grab the source directly which I did for the last metamail-version I have on my system too because the genpatches just did not work.

------- Comment #8 From Kurt Lieber 2004-05-11 11:11:25 0000 -------
You're welcome to submit an updated ebuild.  Otherwise, you can also unmask the
package as described in the /usr/portage/profiles/package.mask file.

------- Comment #9 From Seemant Kulleen (RETIRED) 2004-05-11 11:16:25 0000 -------
I'm on this, give me a few minutes

------- Comment #10 From Jason Short 2004-05-11 11:57:56 0000 -------
Created an attachment (id=31204) [details]
ebuild using new debian patch

------- Comment #11 From Seemant Kulleen (RETIRED) 2004-05-11 12:08:34 0000 -------
Jason, thanks for the ebuild -- I'd already had one in the works with a
different patch and a different tweak in it.  Anyway, people, 2.7.45.3 is in
portage -- Arch maintainers, please test and stabilise.

------- Comment #12 From Kurt Lieber 2004-05-11 12:10:21 0000 -------
arches -- please test/mark stable.

------- Comment #13 From Bryan Østergaard (RETIRED) 2004-05-11 15:55:46 0000 -------
Stable on alpha.

------- Comment #14 From Jason Wever (RETIRED) 2004-05-11 17:21:58 0000 -------
Are the automake and autoconf errors that show up right after the patch
expected?

 * Applying metamail_2.7-45.3.diff...                                     [ ok
]
ls: ./acinclude.m4: No such file or directory
automake: Makefile.am: required file `./NEWS' not found
automake: Makefile.am: required file `./AUTHORS' not found
automake: Makefile.am: required file `./ChangeLog' not found
FATAL ERROR: Autoconf version 2.50 or higher is required for this script
FATAL ERROR: Autoconf version 2.50 or higher is required for this script
>>> Source unpacked.

------- Comment #15 From Jason Wever (RETIRED) 2004-05-11 20:35:35 0000 -------
Once seemant's patch-fu was added, it now works great and spits out no errors.

Stable on sparc

------- Comment #16 From Jonas Fährmann 2004-05-12 02:51:59 0000 -------
When is the patched ebuild supposed to be supplied with the portage tree
officially - any schedule yet?
The masking still breaks emerge -u world when using sylpheed-claws.
How ca I apply the patch? sorry I

------- Comment #17 From Jonas Fährmann 2004-05-12 02:51:59 0000 -------
When is the patched ebuild supposed to be supplied with the portage tree
officially - any schedule yet?
The masking still breaks emerge -u world when using sylpheed-claws.
How ca I apply the patch? sorry I´m still n00b :-/

------- Comment #18 From Jonas Fährmann 2004-05-12 04:54:05 0000 -------
I just found http://www.gentoo.org/doc/en/portage-manual.xml#doc_chap3_sect2
again, so now I should be able to apply the fixed ebuild. 

------- Comment #19 From Thierry Carrez (RETIRED) 2004-05-15 11:08:06 0000 -------
Target keywords = "x86 ppc alpha ia64 sparc s390 ~amd64 ~hppa"
ppc, ia64, s390 : please mark stable

------- Comment #20 From Michael McCabe (RETIRED) 2004-05-20 18:33:01 0000 -------
Stable on s390

------- Comment #21 From Thierry Carrez (RETIRED) 2004-05-21 00:58:00 0000 -------
ppc, ia64 : please mark stable

------- Comment #22 From Luca Barbato 2004-05-21 07:10:38 0000 -------
Marked ppc

------- Comment #23 From Thierry Carrez (RETIRED) 2004-05-21 12:44:04 0000 -------
GLSA 200405-17

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug