Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 88862
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
xv.pdf xv.pdf (bugtray email by Bruno Rohee) application/pdf Carsten Lohrke 2005-04-13 07:36 0000 52.21 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 88862 depends on: Show dependency tree
Bug 88862 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-04-12 07:56 0000
TITLE:
KDE kdelibs PCX Image Buffer Overflow Vulnerability

SECUNIA ADVISORY ID:
SA14908

VERIFY ADVISORY:
http://secunia.com/advisories/14908/

CRITICAL:
Highly critical

IMPACT:
System access

WHERE:
From remote

SOFTWARE:
KDE 3.x
http://secunia.com/product/219/

DESCRIPTION:
Bruno Rohee has reported a vulnerability in KDE kdelibs, which
potentially can be exploited by malicious people to compromise a
vulnerable system.

The vulnerability is caused due to an error in the kimgio component
when processing PCX image files. This may be exploited via a
specially crafted image file to execute arbitrary code via an
application linked against the vulnerable library.

The vulnerability has been reported in KDE 3.4.0. Other version may
also be affected.

SOLUTION:
Do not open untrusted images in applications linked against the
vulnerable library.

PROVIDED AND/OR DISCOVERED BY:
Bruno Rohee

ORIGINAL ADVISORY:
KDE bug report:
http://bugs.kde.org/show_bug.cgi?id=102328

SUSE advisory:
http://www.novell.com/linux/security/advisories/2005_22_kdelibs3.html

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-04-12 07:56:47 0000 -------
kde please advise.

------- Comment #2 From Carsten Lohrke 2005-04-13 07:36:01 0000 -------
Created an attachment (id=56163) [details]
xv.pdf (bugtray email by Bruno Rohee)

Once again this is a general media-gfx/xv issue. According to Dirk Mueller
(kde.org) there are still issues neither covered by the bug report nor the
Secunia/Suse advisories.

------- Comment #3 From Thierry Carrez (RETIRED) 2005-04-13 08:22:55 0000 -------
Carlo: what does the kdelibs PCX loading thing has to do with XV
vulnerabilities ? It shares the same code ?

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-04-13 08:44:59 0000 -------
Turns out that it has nothing to do with the xv code, though the problem is
similar.

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-04-20 00:31:54 0000 -------
kde will you wait for upstream to release a fixed version or patch the current
ebuild?

------- Comment #6 From Gregorio Guidi (RETIRED) 2005-04-20 01:09:08 0000 -------
Upstrem will officially release a patch really soon.

------- Comment #7 From Carsten Lohrke 2005-04-20 07:03:09 0000 -------
It just looks like we don't get a patch for KDE 3.2.3. Does anyone volunteer?

------- Comment #8 From Carsten Lohrke 2005-04-20 09:09:50 0000 -------
Grabed the 3.2 branch stuff, which seems to be fixed, patch in the works.

Marcus: cc'ing you in advance, doesn't harm if the patch is inspected by a few more than my two eyes.

------- Comment #9 From Carsten Lohrke 2005-04-20 15:06:46 0000 -------
Well, just did it. Herds: As this commit fixes Bug 81110, too, please take the
chance and mark net-dns/libidn-0.5.13 stable before, if you don't have already.

<<< kdelibs-3.2.3-r8.ebuild
<<< kdelibs-3.2.3-r9.ebuild


Thanks.

------- Comment #10 From Lars Weiler (RETIRED) 2005-04-20 17:02:44 0000 -------
You meant

<<< kdelibs-3.3.2-r8.ebuild
<<< kdelibs-3.2.3-r9.ebuild

right?

------- Comment #11 From Sune Kloppenborg Jeppesen 2005-04-20 22:42:28 0000 -------
According to the Changelog it is both the 3.2.x and 3.3.x series:

kdelibs-3.2.3-r9
kdelibs-3.3.2-r8

Arches please test and mark stable.

------- Comment #12 From Carsten Lohrke 2005-04-21 04:00:51 0000 -------
Um, right. The ebuilds looked too similar. :| 

------- Comment #13 From Michael Hanselmann (hansmi) (RETIRED) 2005-04-21 11:39:15 0000 -------
Pylon already marked them stable. Removing ppc@g.o from CC.

------- Comment #14 From Gustavo Zacarias (RETIRED) 2005-04-21 13:04:31 0000 -------
sparc stable.

------- Comment #15 From Bryan Østergaard (RETIRED) 2005-04-22 02:36:24 0000 -------
Stable on alpha and ia64.

------- Comment #16 From Markus Rothe 2005-04-22 11:11:28 0000 -------
stable on ppc64

------- Comment #17 From Sune Kloppenborg Jeppesen 2005-04-23 00:28:32 0000 -------
GLSA 200504-22

hppa, mips remember to mark stable to benifit from GLSA.

------- Comment #18 From Carsten Lohrke 2005-05-03 16:24:46 0000 -------
The issued patch broke reading of .rgb files ( which were not supported by KDE
3.2), so 

<<< files/digest-kdelibs-3.3.2-r9

Herds, please...

------- Comment #19 From Markus Rothe 2005-05-04 09:35:20 0000 -------
stable on ppc64

------- Comment #20 From Michael Hanselmann (hansmi) (RETIRED) 2005-05-04 11:55:33 0000 -------
Stable on ppc.

------- Comment #21 From Jan Brinkmann (RETIRED) 2005-05-04 12:15:02 0000 -------
stable on amd64

------- Comment #22 From Bryan Østergaard (RETIRED) 2005-05-04 23:58:18 0000 -------
Stable on alpha + ia64.

------- Comment #23 From Michael Hanselmann (hansmi) (RETIRED) 2005-05-05 04:16:30 0000 -------
Stable on hppa.

------- Comment #24 From Jason Wever (RETIRED) 2005-05-05 20:41:12 0000 -------
SPARC'd

------- Comment #25 From Sune Kloppenborg Jeppesen 2005-05-07 10:52:43 0000 -------
Closing again.

mips please remember to mark stable.

------- Comment #26 From Hardave Riar (RETIRED) 2005-07-07 22:50:06 0000 -------
Stable on mips.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug