Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 88862 - kde-base/kdelibs PCX Image Buffer Overflow Vulnerability
Summary: kde-base/kdelibs PCX Image Buffer Overflow Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.kde.org/info/security/advi...
Whiteboard: B2 [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-04-12 07:56 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-07-07 22:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
xv.pdf (bugtray email by Bruno Rohee) (xv.pdf,52.21 KB, application/pdf)
2005-04-13 07:36 UTC, Carsten Lohrke (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-12 07:56:08 UTC
TITLE:
KDE kdelibs PCX Image Buffer Overflow Vulnerability

SECUNIA ADVISORY ID:
SA14908

VERIFY ADVISORY:
http://secunia.com/advisories/14908/

CRITICAL:
Highly critical

IMPACT:
System access

WHERE:
From remote

SOFTWARE:
KDE 3.x
http://secunia.com/product/219/

DESCRIPTION:
Bruno Rohee has reported a vulnerability in KDE kdelibs, which
potentially can be exploited by malicious people to compromise a
vulnerable system.

The vulnerability is caused due to an error in the kimgio component
when processing PCX image files. This may be exploited via a
specially crafted image file to execute arbitrary code via an
application linked against the vulnerable library.

The vulnerability has been reported in KDE 3.4.0. Other version may
also be affected.

SOLUTION:
Do not open untrusted images in applications linked against the
vulnerable library.

PROVIDED AND/OR DISCOVERED BY:
Bruno Rohee

ORIGINAL ADVISORY:
KDE bug report:
http://bugs.kde.org/show_bug.cgi?id=102328

SUSE advisory:
http://www.novell.com/linux/security/advisories/2005_22_kdelibs3.html
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-12 07:56:47 UTC
kde please advise.
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2005-04-13 07:36:01 UTC
Created attachment 56163 [details]
xv.pdf (bugtray email by Bruno Rohee)

Once again this is a general media-gfx/xv issue. According to Dirk Mueller
(kde.org) there are still issues neither covered by the bug report nor the
Secunia/Suse advisories.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-04-13 08:22:55 UTC
Carlo: what does the kdelibs PCX loading thing has to do with XV vulnerabilities ? It shares the same code ?
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-13 08:44:59 UTC
Turns out that it has nothing to do with the xv code, though the problem is similar.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-20 00:31:54 UTC
kde will you wait for upstream to release a fixed version or patch the current ebuild?
Comment 6 Gregorio Guidi (RETIRED) gentoo-dev 2005-04-20 01:09:08 UTC
Upstrem will officially release a patch really soon.
Comment 7 Carsten Lohrke (RETIRED) gentoo-dev 2005-04-20 07:03:09 UTC
It just looks like we don't get a patch for KDE 3.2.3. Does anyone volunteer?
Comment 8 Carsten Lohrke (RETIRED) gentoo-dev 2005-04-20 09:09:50 UTC
Grabed the 3.2 branch stuff, which seems to be fixed, patch in the works.

Marcus: cc'ing you in advance, doesn't harm if the patch is inspected by a few more than my two eyes.
Comment 9 Carsten Lohrke (RETIRED) gentoo-dev 2005-04-20 15:06:46 UTC
Well, just did it. Herds: As this commit fixes Bug 81110, too, please take the chance and mark net-dns/libidn-0.5.13 stable before, if you don't have already.

<<< kdelibs-3.2.3-r8.ebuild
<<< kdelibs-3.2.3-r9.ebuild


Thanks.
Comment 10 Lars Weiler (RETIRED) gentoo-dev 2005-04-20 17:02:44 UTC
You meant

<<< kdelibs-3.3.2-r8.ebuild
<<< kdelibs-3.2.3-r9.ebuild

right?
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-20 22:42:28 UTC
According to the Changelog it is both the 3.2.x and 3.3.x series:

kdelibs-3.2.3-r9
kdelibs-3.3.2-r8

Arches please test and mark stable.
Comment 12 Carsten Lohrke (RETIRED) gentoo-dev 2005-04-21 04:00:51 UTC
Um, right. The ebuilds looked too similar. :| 
Comment 13 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-04-21 11:39:15 UTC
Pylon already marked them stable. Removing ppc@g.o from CC.
Comment 14 Gustavo Zacarias (RETIRED) gentoo-dev 2005-04-21 13:04:31 UTC
sparc stable.
Comment 15 Bryan Østergaard (RETIRED) gentoo-dev 2005-04-22 02:36:24 UTC
Stable on alpha and ia64.
Comment 16 Markus Rothe (RETIRED) gentoo-dev 2005-04-22 11:11:28 UTC
stable on ppc64
Comment 17 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-23 00:28:32 UTC
GLSA 200504-22

hppa, mips remember to mark stable to benifit from GLSA.
Comment 18 Carsten Lohrke (RETIRED) gentoo-dev 2005-05-03 16:24:46 UTC
The issued patch broke reading of .rgb files ( which were not supported by KDE 3.2), so 

<<< files/digest-kdelibs-3.3.2-r9

Herds, please...
Comment 19 Markus Rothe (RETIRED) gentoo-dev 2005-05-04 09:35:20 UTC
stable on ppc64
Comment 20 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-05-04 11:55:33 UTC
Stable on ppc.
Comment 21 Jan Brinkmann (RETIRED) gentoo-dev 2005-05-04 12:15:02 UTC
stable on amd64
Comment 22 Bryan Østergaard (RETIRED) gentoo-dev 2005-05-04 23:58:18 UTC
Stable on alpha + ia64.
Comment 23 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-05-05 04:16:30 UTC
Stable on hppa.
Comment 24 Jason Wever (RETIRED) gentoo-dev 2005-05-05 20:41:12 UTC
SPARC'd
Comment 25 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-07 10:52:43 UTC
Closing again.

mips please remember to mark stable.
Comment 26 Hardave Riar (RETIRED) gentoo-dev 2005-07-07 22:50:06 UTC
Stable on mips.