First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 42735
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Christian Birchinger <joker@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 42735 depends on: Show dependency tree
Bug 42735 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-02-24 04:01 0000
The vulnerabilities are caused due to boundary errors in nanohttp and
nanoftp when parsing overly long URIs. This can be exploited to cause
a buffer overflow by supplying an overly long URI (about 4096
bytes).

Successful exploitation may potentially allow execution of arbitrary
code.


Reproducible: Always
Steps to Reproduce:
1.<none>
2.
3.

Actual Results:  
<none>

Expected Results:  
<none>

2.6.6 is already in portage but not marked stable yet. It would be a good
idea to mark it stable soon.

(Using normal Severity since it's just not marked stable)

------- Comment #1 From Christian Birchinger 2004-02-24 04:26:35 0000 -------
Package marked stable. If you don't want to release a GLSA just close this bug.
Otherwise close it after releasing one :)

------- Comment #2 From Rajiv Aaron Manglani 2004-03-05 09:10:43 0000 -------
i think we should send a glsa. any one second this?

------- Comment #3 From Spider (RETIRED) 2004-03-05 13:16:13 0000 -------
yeah, tha t would be fitting.

------- Comment #4 From Tim Yamin (RETIRED) 2004-03-05 13:36:00 0000 -------
http://dev.gentoo.org/~plasmaroo/glsa-test/frame-view.php?id=200403-01

------- Comment #5 From solar 2004-03-05 15:41:20 0000 -------
re #4 looks good

------- Comment #6 From Kurt Lieber 2004-03-28 03:20:11 0000 -------
closing old bug.  GLSA 200403-01

------- Comment #7 From Thierry Carrez (RETIRED) 2004-10-04 07:20:11 0000 -------
*** Bug 66309 has been marked as a duplicate of this bug. ***

First Last Prev Next    No search results available      Search page      Enter new bug