First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 69624
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Pablo De Nápoli <pdenapo@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 69624 depends on: 69936 Show dependency tree
Bug 69624 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-31 07:53 0000
Acording to the official Koffice release notes, koffice-1.3.4 has an integer
overflow vulnerability fix in KWord's PDF import filter which is weak against
compiler optimization.

A patch is available at

http://download.kde.org/stable/koffice-1.3.4/src/patch/koffice_xpdf_1_3_4_security_integer_overflow.diff

Please patch the source with it.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

------- Comment #1 From Thierry Carrez (RETIRED) 2004-10-31 08:35:00 0000 -------
Looks like the original patch introduced in GLSA 200410-30 and bug 68558 may
not be sufficient...

KDE team : We might have to repatch this :/

------- Comment #2 From Simone Gotti (RETIRED) 2004-10-31 08:50:01 0000 -------
The reported link doesn't works for me.
This one works
ftp://ftp.kde.org/pub/kde/stable/koffice-1.3.4/src/patch/koffice_1_3_4_xpdf_security_integer_overflow.diff

BTW I've noticed that in KDECVS a similar patch was applied also to kpdf, but didn't find any report:

http://lists.kde.org/?l=kde-cvs&m=109895739822113&w=2 >> IT'S WRONG
http://lists.kde.org/?l=kde-cvs&m=109895658125554&w=2 >> IT'S RIGHT BUT APPLIED ON THE UPPER ONE.

------- Comment #3 From Carsten Lohrke 2004-10-31 09:06:39 0000 -------
Can't find/verify gpg signature. The patch looks good, though.

<<< koffice-1.3.3-r2.ebuild
<<< koffice-1.3.4-r1.ebuild

Arch herds, I have to ask you again: Please mark either one of the above ebuilds stable.

ppc64: Would be nice, if you would use the "second chance". I can dump the old ebuilds in one rush then.

------- Comment #4 From Michael Hanselmann (hansmi) (RETIRED) 2004-10-31 10:44:42 0000 -------
Stable on ppc.

------- Comment #5 From Jason Wever (RETIRED) 2004-10-31 16:55:29 0000 -------
koffice-1.3.3-r2 stable on sparc

------- Comment #6 From Bryan Østergaard (RETIRED) 2004-11-01 03:24:03 0000 -------
1.3.4-r1 stable on alpha.

------- Comment #7 From Jeremy Huddleston (RETIRED) 2004-11-02 12:38:55 0000 -------
1.3.4-r1 stable on amd64

------- Comment #8 From Markus Rothe 2004-11-02 13:28:14 0000 -------
1.3.4-r1 stable on ppc64

------- Comment #9 From Thierry Carrez (RETIRED) 2004-11-03 03:12:12 0000 -------
Looks the same as (still not public) bug 69662 to me. Patches are different,
but I would say they patch the same thing. Can someone with access
double-confirm this is a different issue ?

------- Comment #10 From Carsten Lohrke 2004-11-03 09:24:17 0000 -------
Koon: Yes, it is. Koffice is fixed, kdegraphics fixes follow in a few minutes.

------- Comment #11 From Thierry Carrez (RETIRED) 2004-11-03 12:30:42 0000 -------
Thanks Carsten for clarification.
We'll probably group xpdf 64 bit GLSAs (or update the old xpdf one).

------- Comment #12 From Thierry Carrez (RETIRED) 2004-11-05 04:53:41 0000 -------
Will be released as a 200410-30 update when bug 69936 will be done.

------- Comment #13 From Thierry Carrez (RETIRED) 2004-11-06 05:33:51 0000 -------
GLSA 200410-30:02 update out

First Last Prev Next    No search results available      Search page      Enter new bug