Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 78128
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
CAN-2005-0064.patch xpdf-CAN-2005-0064.patch patch Thierry Carrez (RETIRED) 2005-01-15 12:41 0000 773 bytes Details | Diff
2.8.1-r1_2.8.2.diff diff between gpdf 2.8.1-r1 and 2.8.2 patch Joe McCann (RETIRED) 2005-01-15 12:58 0000 656 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 78128 depends on: Show dependency tree
Bug 78128 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-01-15 12:40 0000
A new Xpdf vulnerability will be disclosed on January 18. This will impact
(again) GPdf. This is confidential, so we can't commit the fix to Portage until
disclosure date. Please prepare an ebuild and if ready attach it to this bug so
that we can call arch pre-testing.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-01-15 12:41:25 0000 -------
Created an attachment (id=48572) [details]
xpdf-CAN-2005-0064.patch

Patch from RedHat. An official Xpdf patch will be available on Jan 18, but if
we can be ready before that, all the better.

------- Comment #2 From Joe McCann (RETIRED) 2005-01-15 12:58:11 0000 -------
Created an attachment (id=48575) [details]
diff between gpdf 2.8.1-r1 and 2.8.2

Gpdf also needs a bump to version 2.8.2 which includes the last security patch.
This is the diff between the 2.8.2 ebuild and 2.8.1-r1. I might not be
available very often this week, so somebody else may need to add it. Changed
the patched file location to xpdf/foo.cc so we can apply it from ${S}

------- Comment #3 From Thierry Carrez (RETIRED) 2005-01-15 13:22:39 0000 -------
Thanks joem. I suppose you keyworded it x86 because you tested it with success
on that platform.

obz: please test and report success on ppc
kloeri: please test and report success on alpha
absinthe: please test and report success on amd64
gustavoz: please test and report success on sparc

------- Comment #4 From Gustavo Zacarias (RETIRED) 2005-01-17 05:38:24 0000 -------
sparc is happy, though the patch is still wrong (outside ${S}/xpdf), forgot to
upload the corrected one?

------- Comment #5 From Bryan Østergaard (RETIRED) 2005-01-17 13:35:53 0000 -------
Alpha works.

------- Comment #6 From Thierry Carrez (RETIRED) 2005-01-18 03:23:10 0000 -------
This should go public sometime today. Still missing amd64/ppc testing, adding
kugelfang and SeJo to help.

------- Comment #7 From Thierry Carrez (RETIRED) 2005-01-18 06:50:09 0000 -------
OK apparently this patch is not sufficient. We'll just wait for the upstream
official patch... sorry for wasting your time, folks.

------- Comment #8 From Thierry Carrez (RETIRED) 2005-01-19 00:34:58 0000 -------
Gnome team, please adapt gpdf-2.8.2 so that it makes use of official and public
xpdf-3.00pl3.patch from bug 77888.

------- Comment #9 From Mike Gardiner (RETIRED) 2005-01-20 01:05:56 0000 -------
Added an updated 2.8.2, marked stable on x86 and ppc.

------- Comment #10 From Gustavo Zacarias (RETIRED) 2005-01-20 06:56:19 0000 -------
sparc-a-go-go.

------- Comment #11 From Bryan Østergaard (RETIRED) 2005-01-20 10:15:28 0000 -------
Alpha stable.

------- Comment #12 From Hardave Riar (RETIRED) 2005-01-21 03:23:38 0000 -------
Stable on mips.

------- Comment #13 From Danny van Dyk (RETIRED) 2005-01-21 12:32:11 0000 -------
Stable on amd64.

------- Comment #14 From Thierry Carrez (RETIRED) 2005-01-21 12:46:50 0000 -------
GLSA 200501-28
hppa, ia64 please mark stable to benefit from GLSA

------- Comment #15 From René Nussbaumer 2005-06-26 05:41:20 0000 -------
Already stable on hppa

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug