Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 140885 - kde-misc/krusader < 1.70.1 - passwords sometimes stored in cleartext by the bookmark manager (CVE-2006-3816)
Summary: kde-misc/krusader < 1.70.1 - passwords sometimes stored in cleartext by the b...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://krusader.sourceforge.net/phpBB...
Whiteboard: B4 [noglsa] jaervosz
Keywords:
: 140510 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-07-18 02:22 UTC by Dirk Eschler
Modified: 2006-08-01 10:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dirk Eschler 2006-07-18 02:22:27 UTC
We have just released krusader-1.70.1. This is a maintenance release which closes a security hole in the bookmark manager. Furthermore this version includes several crash fixes that have been backported from the head branch.

For details about the security problem, please see:
http://krusader.sourceforge.net/phpBB/viewtopic.php?p=7965
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-23 12:34:21 UTC
KDE please advise.
Comment 2 Diego Elio Pettenò (RETIRED) gentoo-dev 2006-07-23 13:14:09 UTC
Bump done.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-23 13:39:22 UTC
Thx Diego.

Arches please test and mark stable.
Comment 4 Joshua Jackson (RETIRED) gentoo-dev 2006-07-23 16:13:15 UTC
works great on x86
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2006-07-24 23:24:31 UTC
ppc64 stable
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2006-07-25 09:34:57 UTC
ppc stable
Comment 7 Diego Elio Pettenò (RETIRED) gentoo-dev 2006-07-28 00:19:32 UTC
*** Bug 140510 has been marked as a duplicate of this bug. ***
Comment 8 Jason Wever (RETIRED) gentoo-dev 2006-07-28 07:36:02 UTC
Stable on SPARC
Comment 9 Stefan Cornelius (RETIRED) gentoo-dev 2006-07-28 07:38:38 UTC
lets start with the glsa-vote, voting "no".
Comment 10 Wolf Giesen (RETIRED) gentoo-dev 2006-07-28 10:04:50 UTC
Phh. "No".
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2006-07-29 05:32:09 UTC
I'll vote yes, so that you need one more 'no' to close it :P
Comment 12 Michael Weyershäuser 2006-08-01 00:26:24 UTC
Tested and working fine on amd64

emerge --info
Portage 2.1-r1 (default-linux/amd64/2006.0, gcc-3.4.6, glibc-2.3.6-r4, 2.6.17-suspend2-r3-Dudebox-Edition x86_64)
=================================================================
System uname: 2.6.17-suspend2-r3-Dudebox-Edition x86_64 unknown
Gentoo Base System version 1.6.15
ccache version 2.3 [enabled]
app-admin/eselect-compiler: [Not Present]
dev-lang/python:     2.4.3-r1
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.3
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.59-r7
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.13-r3
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS="amd64"
AUTOCLEAN="yes"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=k8 -O2 -pipe -msse3"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf /etc/revdep-rebuild /etc/terminfo"
CXXFLAGS="-march=k8 -O2 -pipe -msse3"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig ccache collision-protect distlocks metadata-transfer multilib-strict parallel-fetch sandbox sfperms strict test userfetch userpriv usersandbox"
GENTOO_MIRRORS="ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp:///ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/"
LINGUAS="de"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude='/distfiles' --exclude='/local' --exclude='/packages'"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://server/gentoo-portage"
USE="amd64 X alsa arts avi berkdb bitmap-fonts cli crypt cups dlloader dri eds emboss encode foomaticdb fortran gif gnome gpm gstreamer gtk gtk2 imlib ipv6 isdnlog jpeg kde kdeenablefinal lzw lzw-tiff mp3 mpeg ncurses nls nptl opengl pam pcre pdflib perl png pppd python qt qt3 qt4 quicktime readline reflection sdl session spell spl ssl tcpd tiff truetype-fonts type1-fonts unicode usb userlocales xorg xpm xv zlib elibc_glibc input_devices_keyboard input_devices_mouse input_devices_evdev kernel_linux linguas_de userland_GNU video_cards_dummy"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LDFLAGS, MAKEOPTS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 13 Simon Stelling (RETIRED) gentoo-dev 2006-08-01 02:08:46 UTC
amd64 done, sorry about the delay
Comment 14 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-01 04:34:14 UTC
A weak yes from me.
Comment 15 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-08-01 10:34:15 UTC
i vote no. haha! what's happening now ? :
Comment 16 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-08-01 10:34:15 UTC
i vote no. haha! what's happening now ? :þ
Comment 17 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-01 10:45:26 UTC
2 NO and 1
Comment 18 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-01 10:45:26 UTC
2 NO and 1½ YES -> no GLSA.

Feel free to reopen if you disagree.