Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 60855
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
QTP Patch ripped from Suse's SRPM patch Marc Ballarin 2004-08-19 09:18 0000 8.15 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 60855 depends on: Show dependency tree
Bug 60855 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-08-18 23:58 0000
Mandrake released the following:


------- Comment #1 From Sune Kloppenborg Jeppesen 2004-08-18 23:58:36 0000 -------
Mandrake released the following:

 Problem Description: 
 
 Chris Evans discovered a heap-based overflow in the QT library when 
  handling 8-bit RLE encoded BMP files. This vulnerability could allow 
  for the compromise of the account used to view or browse malicious 
  BMP files. On subsequent investigation, it was also found that the 
  handlers for XPM, GIF, and JPEG image types were also faulty. 
   
  These problems affect all applications that use QT to handle image 
  files, such as QT-based image viewers, the Konqueror web browser, 
  and others.

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-08-19 00:02:13 0000 -------
Not much info yet.

kde please verify wether 3.3.3 solves this problem?

I'm not sure that the lines below from the Changelog fixes this problem:

- QImage
        Included fix for buffer overflow in libPNG.
        Fixed bug that made copy constructor not copy the entire image.
        Allow XPM images with colors that have more than one word in the
        name.
        Fixed crash when trying to load a corrupt/invalid BMP image.
        Fixed crash when trying to load a corrupt/invalid GIF image.
        Fixed crash when trying to load a JPEG image that is too big.
        Fixed bug that caused dotsPerMeter() to be ignored when saving
        JPEG images.

------- Comment #3 From Carsten Lohrke 2004-08-19 04:47:03 0000 -------
Yes it is the libpng issue. Arch teams, please mark stable.

------- Comment #4 From Aron Griffis (RETIRED) 2004-08-19 05:25:44 0000 -------
Please clarify what needs to be marked stable.

------- Comment #5 From Caleb Tennis 2004-08-19 05:51:43 0000 -------
I know nothing of this bug, nor do I know if 3.3.3 has the fix for it.  I've
heard nothing from the Qt developers on the matter.

Also, my recommendation to the arches is to not just blindly bump this to
stable as we don't know enough if 3.3.3 introduces any "regressions" yet from
3.3.2, particularly to KDE.

------- Comment #6 From Carsten Lohrke 2004-08-19 06:05:36 0000 -------
Sorry Caleb, but I went ahead for x86 already. Chris Evans discovered
vulnerabilities in libpng lately (http://secunia.com/advisories/12219/) and I
guess this is just part of what he found.

------- Comment #7 From Sune Kloppenborg Jeppesen 2004-08-19 07:15:20 0000 -------
Back to ebuild status and uncc'ing arches.

It's not entirely clear what Mandrake patched but it appears that qt 3.3.3 contains security fixes. Caleb will you look into this? 

If qt 3.3.2 is vulnerable to the libpng issue we need to bump to 3.3.3 or a patched version.

------- Comment #8 From Marc Ballarin 2004-08-19 09:11:46 0000 -------
It's the libpng bug + several bugs in QT itself.
Affected are BMP, XPM and JPEG.

------- Comment #9 From Marc Ballarin 2004-08-19 09:18:39 0000 -------
Created an attachment (id=37737) [details]
Patch ripped from Suse's SRPM

Applies against 3.3.2 with a few offsets. Not compile tested.

------- Comment #10 From Chris White (RETIRED) 2004-08-19 10:02:14 0000 -------
*** Bug 60902 has been marked as a duplicate of this bug. ***

------- Comment #11 From Pieter Van den Abeele 2004-08-19 11:52:42 0000 -------
Hi,

what needs to be marked stable?

Pieter

------- Comment #12 From Pieter Van den Abeele 2004-08-19 13:22:04 0000 -------
If qt-3.3.3 turns out to have the fixes, it can go stable on ppc. I've tested
it.

------- Comment #13 From Carsten Lohrke 2004-08-19 13:27:36 0000 -------
Qt-3.3.3 has the fixes, but there's still Caleb's veto, because Trolltech
didn't announced anything yet.

------- Comment #14 From SpanKY 2004-08-19 19:42:49 0000 -------
they didnt announce it but if you review the changelog as noted in Bug 60902:
http://www.trolltech.com/developer/changes/changes-3.3.3.html

it, at the very least, mentions the libpng bug

------- Comment #15 From Gustavo Zacarias (RETIRED) 2004-08-20 08:10:51 0000 -------
qt-3.3.3 looks good on sparc, but i'll wait for caleb/weeve's take on this one.

------- Comment #16 From Caleb Tennis 2004-08-20 08:16:27 0000 -------
The bump to stable is fine with me - I just wanted to make sure that people
understand that there have been instances before where upgrading to a new minor
version of Qt caused problems with KDE installations which required a re-emerge
of kde - and a lot of end user griping :)

------- Comment #17 From Gustavo Zacarias (RETIRED) 2004-08-20 08:38:22 0000 -------
Okie dokie, sparc stable then.

------- Comment #18 From Pieter Van den Abeele 2004-08-20 08:58:12 0000 -------
stable on ppc

------- Comment #19 From Tom Gall 2004-08-20 10:30:20 0000 -------
stable on ppc64

------- Comment #20 From Danny van Dyk (RETIRED) 2004-08-20 10:42:07 0000 -------
stable on amd64

------- Comment #21 From SpanKY 2004-08-20 17:34:23 0000 -------
hppa stable

------- Comment #22 From Bryan Østergaard (RETIRED) 2004-08-20 23:50:11 0000 -------
Stable on alpha.

------- Comment #23 From Sune Kloppenborg Jeppesen 2004-08-21 07:44:05 0000 -------
This is ready for GLSA. Security please draft.

------- Comment #24 From Joshua J. Berry (CondorDes) (RETIRED) 2004-08-21 12:30:14 0000 -------
GLSA drafted.  Security team, please review.

------- Comment #25 From Joshua J. Berry (CondorDes) (RETIRED) 2004-08-22 14:24:30 0000 -------
GLSA 200408-20.

------- Comment #26 From Joshua J. Berry (CondorDes) (RETIRED) 2004-08-22 14:24:44 0000 -------
GLSA 200408-20.

------- Comment #27 From Hardave Riar (RETIRED) 2004-08-26 01:00:54 0000 -------
Stable on mips.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug