First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 68616
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Steph L <linux4ibook@free.fr>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 68616 depends on: Show dependency tree
Bug 68616 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-23 00:29 0000
Versions before 1.14 are vulnerable to the following problem : 
http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=false

See perl bugs : 
http://rt.cpan.org/NoAuth/Bug.html?id=8076
http://rt.cpan.org/NoAuth/Bug.html?id=8077

People using Archive-zip in amavisd-new, and some other 
email filtering applications really need this update

Reproducible: Always
Steps to Reproduce:
1.
2.
3. 




Solution : 
 cp Archive-Zip-1.12.ebuild  Archive-Zip-1.14.ebuild 
 ebuild Archive-Zip-1.14.ebuild digest

------- Comment #1 From Chris White (RETIRED) 2004-10-23 07:11:21 0000 -------
This looks to be a security bug.  I'm re-assigning it to the security team for
overview.

------- Comment #2 From Matthias Geerdsen 2004-10-23 07:52:26 0000 -------
perl team, pls bump the ebuild

------- Comment #3 From Michael Cummings (RETIRED) 2004-10-23 18:06:15 0000 -------
Bumped, tested, marked for sparc and x86. PPC, can you check it, confirm it,
and mark it?

------- Comment #4 From Michael Cummings (RETIRED) 2004-10-23 18:45:36 0000 -------
darkspectre worked with me in irc and confirmed this for ppc. marking stable
now - security folks, its all up to you for a glsa if you want it.

------- Comment #5 From Matthias Geerdsen 2004-10-24 03:03:30 0000 -------
adjusting Severity, removing ppc since it's already stable on ppc

__

alpha and amd64, please test Archive-Zip-1.14 and mark it stable if possible

current KEYWORDS="x86 sparc ppc"
target KEYWORDS="x86 amd64 ppc sparc alpha"

------- Comment #6 From Bryan Østergaard (RETIRED) 2004-10-24 06:32:54 0000 -------
Stable on alpha.

------- Comment #7 From Matthias Geerdsen 2004-10-25 01:53:18 0000 -------
security,
while we are waiting for the last arch to test/mark stable, pls vote on a GLSA

------- Comment #8 From Thierry Carrez (RETIRED) 2004-10-25 02:27:23 0000 -------
This allows to bypass antivirus security, so I would issue one (Low ?), yes.

------- Comment #9 From Karol Wojtaszek (RETIRED) 2004-10-25 15:22:54 0000 -------
Stable on amd64.

------- Comment #10 From Steph L 2004-10-26 15:47:36 0000 -------
The FreeBSD folks have updated their port to 1.14
There is now an official Amavis Security Announcement :  

http://marc.theaimsgroup.com/?l=amavis-user&m=109882288027259&w=2
http://marc.theaimsgroup.com/?l=amavis-user&m=109882351729093&w=2

------- Comment #11 From Thierry Carrez (RETIRED) 2004-10-27 05:10:17 0000 -------
We'll have a GLSA on that one.

------- Comment #12 From Thierry Carrez (RETIRED) 2004-10-29 06:12:32 0000 -------
GLSA 200410-31

First Last Prev Next    No search results available      Search page      Enter new bug