Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 79183
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
CAN-2005-0102.patch CAN-2005-0102.patch patch Sune Kloppenborg Jeppesen 2005-01-23 02:38 0000 467 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 79183 depends on: 76251 Show dependency tree
Bug 79183 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-01-23 02:35 0000
Max Vozeler discovered an integer overflow in the helper application
camel-lock-helper which runs setuid root or setgid mail inside of
Evolution, a free grouware suite.  A local attacker can cause the
setuid root helper to execute arbitrary code with elevated privileges
via a malicious POP server.

This is public already.

Message by NotZed:
http://lists.ximian.com/archives/public/evolution-patches/2005-January/008672.html

CVS commit:
http://cvs.gnome.org/viewcvs/evolution/camel/camel-lock-helper.c?rev=1.7&hideattic=0&view=log

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-01-23 02:38:32 0000 -------
Created an attachment (id=49262) [details]
CAN-2005-0102.patch

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-01-23 02:41:04 0000 -------
Alastair/Mike please provide an updated ebuild.

------- Comment #3 From Mike Gardiner (RETIRED) 2005-01-23 04:08:18 0000 -------
There are two new ebuilds that include the patch - 2.0.2-r1 and 2.0.3-r1. 

Currently, the keywords for evolution are as follows:

evolution-2.0.2.ebuild:KEYWORDS="x86 amd64 ppc sparc hppa ia64 ~mips alpha"
evolution-2.0.2-r1.ebuild:KEYWORDS="x86 ~amd64 ppc ~sparc ~hppa ~ia64 ~mips ~alpha"
evolution-2.0.3.ebuild:KEYWORDS="~x86 ~amd64 ~ppc ~sparc ~hppa ~ia64 ~mips ~alpha"
evolution-2.0.3-r1.ebuild:KEYWORDS="~x86 ~amd64 ~ppc ~sparc ~hppa ~ia64 ~mips ~alpha"

If all archs could please mark evolution-2.0.2-r1 stable now, and move to evolution-2.0.3-r1 as per usual.

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-01-23 04:16:54 0000 -------
Opening bug.

Arches please test and mark stable.

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-01-23 04:24:12 0000 -------
closing again. Calling individual testers in a moment.

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-01-23 04:32:38 0000 -------
Sorry for the arch noise. This is still only semi-public.

Arches please test and mark 2.0.2-r1 stable:

amd64 -> slarti
sparc -> gustavoz
hppa -> gmsoft
ia64 -> agriffis
alpha -> kloeri

------- Comment #7 From Tom Martin (RETIRED) 2005-01-23 07:11:16 0000 -------
AMD64 done, thanks.

------- Comment #8 From solar 2005-01-23 13:41:03 0000 -------
[ebuild  NS   ] mail-client/evolution-2.0.3-r1  +crypt -debug -doc -ipv6
-kerberos +ldap +mozilla -nntp -pda +spell +ssl 0 kB

Fails to build here with

* Scanning for a open DISPLAY to start Xvfb ...
 * 
 * Unable to start Xvfb.
 * 
 * '/usr/X11R6/bin/Xvfb :17 -screen 0 800x600x24' returns:
 * 
/var/cvsroot/gentoo-x86//eclass/virtualx.eclass: line 71: /usr/X11R6/bin/Xvfb:
No such file or directory
 * 
 * If possible, correct the above error and try your emerge again.
 * 
--------------------------------------------------------------------
I do not have or use framebuffer support. adding liquidx@ to the CC: as he is
the listed maintainer.

------- Comment #9 From Sune Kloppenborg Jeppesen 2005-01-23 13:50:33 0000 -------
Removing liquidx. According to Obz he's no longer maintaining this. Obz please
update metadata.xml and advise on current ebuild.

------- Comment #10 From Mike Gardiner (RETIRED) 2005-01-23 17:53:21 0000 -------
Solar see bug 76251 , regarding USE="minimal" xorg-x11 installs, somehow I
missed it because it's assigned to azarah.

------- Comment #11 From Thierry Carrez (RETIRED) 2005-01-24 05:52:54 0000 -------
Ccing DerCorny for the GLSA draft

------- Comment #12 From Thierry Carrez (RETIRED) 2005-01-24 07:36:13 0000 -------
Public, since Ubuntu leaked it.

------- Comment #13 From Gustavo Zacarias (RETIRED) 2005-01-24 07:56:18 0000 -------
2.0.2-r1 stable on sparc.
sorry for the delay, but i usually lack X access to sparc during weekends.

------- Comment #14 From Bryan Østergaard (RETIRED) 2005-01-24 11:28:37 0000 -------
Alpha stable.

------- Comment #15 From Luke Macken (RETIRED) 2005-01-24 13:43:25 0000 -------
GLSA 200501-35

hppa/ia64: please mark stable to benefit from GLSA.

Thanks to DerCorny for the draft.

------- Comment #16 From René Nussbaumer 2005-06-26 05:46:20 0000 -------
Already stable on hppa. ebuild no longer in portage.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug