Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 60855 - x11-libs/qt Updated qt3 packages fix multiple vulnerabilities
Summary: x11-libs/qt Updated qt3 packages fix multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://archives.neohapsis.com/archive...
Whiteboard: A2 [glsa] condordes
Keywords:
: 60902 (view as bug list)
Depends on:
Blocks:
 
Reported: 2004-08-18 23:58 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2011-10-30 22:40 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Patch ripped from Suse's SRPM (QTP,8.15 KB, patch)
2004-08-19 09:18 UTC, Marc Ballarin
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-18 23:58:36 UTC
Mandrake released the following:

Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-18 23:58:36 UTC
Mandrake released the following:

 Problem Description: 
 
 Chris Evans discovered a heap-based overflow in the QT library when 
  handling 8-bit RLE encoded BMP files. This vulnerability could allow 
  for the compromise of the account used to view or browse malicious 
  BMP files. On subsequent investigation, it was also found that the 
  handlers for XPM, GIF, and JPEG image types were also faulty. 
   
  These problems affect all applications that use QT to handle image 
  files, such as QT-based image viewers, the Konqueror web browser, 
  and others.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-19 00:02:13 UTC
Not much info yet.

kde please verify wether 3.3.3 solves this problem?

I'm not sure that the lines below from the Changelog fixes this problem:

- QImage
        Included fix for buffer overflow in libPNG.
        Fixed bug that made copy constructor not copy the entire image.
        Allow XPM images with colors that have more than one word in the
        name.
        Fixed crash when trying to load a corrupt/invalid BMP image.
        Fixed crash when trying to load a corrupt/invalid GIF image.
        Fixed crash when trying to load a JPEG image that is too big.
        Fixed bug that caused dotsPerMeter() to be ignored when saving
        JPEG images.
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2004-08-19 04:47:03 UTC
Yes it is the libpng issue. Arch teams, please mark stable.
Comment 4 Aron Griffis (RETIRED) gentoo-dev 2004-08-19 05:25:44 UTC
Please clarify what needs to be marked stable.
Comment 5 Caleb Tennis (RETIRED) gentoo-dev 2004-08-19 05:51:43 UTC
I know nothing of this bug, nor do I know if 3.3.3 has the fix for it.  I've heard nothing from the Qt developers on the matter.

Also, my recommendation to the arches is to not just blindly bump this to stable as we don't know enough if 3.3.3 introduces any "regressions" yet from 3.3.2, particularly to KDE.
Comment 6 Carsten Lohrke (RETIRED) gentoo-dev 2004-08-19 06:05:36 UTC
Sorry Caleb, but I went ahead for x86 already. Chris Evans discovered vulnerabilities in libpng lately (http://secunia.com/advisories/12219/) and I guess this is just part of what he found.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-19 07:15:20 UTC
Back to ebuild status and uncc'ing arches.

It's not entirely clear what Mandrake patched but it appears that qt 3.3.3 contains security fixes. Caleb will you look into this? 

If qt 3.3.2 is vulnerable to the libpng issue we need to bump to 3.3.3 or a patched version.
Comment 8 Marc Ballarin 2004-08-19 09:11:46 UTC
It's the libpng bug + several bugs in QT itself.
Affected are BMP, XPM and JPEG.
Comment 9 Marc Ballarin 2004-08-19 09:18:39 UTC
Created attachment 37737 [details, diff]
Patch ripped from Suse's SRPM

Applies against 3.3.2 with a few offsets. Not compile tested.
Comment 10 Chris White (RETIRED) gentoo-dev 2004-08-19 10:02:14 UTC
*** Bug 60902 has been marked as a duplicate of this bug. ***
Comment 11 Pieter Van den Abeele (RETIRED) gentoo-dev 2004-08-19 11:52:42 UTC
Hi,

what needs to be marked stable?

Pieter
Comment 12 Pieter Van den Abeele (RETIRED) gentoo-dev 2004-08-19 13:22:04 UTC
If qt-3.3.3 turns out to have the fixes, it can go stable on ppc. I've tested it.
Comment 13 Carsten Lohrke (RETIRED) gentoo-dev 2004-08-19 13:27:36 UTC
Qt-3.3.3 has the fixes, but there's still Caleb's veto, because Trolltech didn't announced anything yet.
Comment 14 SpanKY gentoo-dev 2004-08-19 19:42:49 UTC
they didnt announce it but if you review the changelog as noted in Bug 60902:
http://www.trolltech.com/developer/changes/changes-3.3.3.html

it, at the very least, mentions the libpng bug
Comment 15 Gustavo Zacarias (RETIRED) gentoo-dev 2004-08-20 08:10:51 UTC
qt-3.3.3 looks good on sparc, but i'll wait for caleb/weeve's take on this one.
Comment 16 Caleb Tennis (RETIRED) gentoo-dev 2004-08-20 08:16:27 UTC
The bump to stable is fine with me - I just wanted to make sure that people understand that there have been instances before where upgrading to a new minor version of Qt caused problems with KDE installations which required a re-emerge of kde - and a lot of end user griping :)
Comment 17 Gustavo Zacarias (RETIRED) gentoo-dev 2004-08-20 08:38:22 UTC
Okie dokie, sparc stable then.
Comment 18 Pieter Van den Abeele (RETIRED) gentoo-dev 2004-08-20 08:58:12 UTC
stable on ppc
Comment 19 Tom Gall (RETIRED) gentoo-dev 2004-08-20 10:30:20 UTC
stable on ppc64
Comment 20 Danny van Dyk (RETIRED) gentoo-dev 2004-08-20 10:42:07 UTC
stable on amd64
Comment 21 SpanKY gentoo-dev 2004-08-20 17:34:23 UTC
hppa stable
Comment 22 Bryan Østergaard (RETIRED) gentoo-dev 2004-08-20 23:50:11 UTC
Stable on alpha.
Comment 23 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-21 07:44:05 UTC
This is ready for GLSA. Security please draft.
Comment 24 Joshua J. Berry (CondorDes) (RETIRED) gentoo-dev 2004-08-21 12:30:14 UTC
GLSA drafted.  Security team, please review.
Comment 25 Joshua J. Berry (CondorDes) (RETIRED) gentoo-dev 2004-08-22 14:24:30 UTC
GLSA 200408-20.
Comment 26 Joshua J. Berry (CondorDes) (RETIRED) gentoo-dev 2004-08-22 14:24:44 UTC
GLSA 200408-20.
Comment 27 Hardave Riar (RETIRED) gentoo-dev 2004-08-26 01:00:54 UTC
Stable on mips.