Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 158219 - app-antivirus/bitdefender-console: cevakrnl.xmd buffer overflow
Summary: app-antivirus/bitdefender-console: cevakrnl.xmd buffer overflow
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.bitdefender.com/KB323-en--...
Whiteboard: B2 [?] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-12-15 07:41 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2007-04-08 22:58 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-15 07:41:26 UTC
Upstream [1] says:

"An update has been issued on August 29,2006 to solve this vulnerability. "

i couldn't find the fixed version number.

Andrej, please can you bump a fixed version? thanks.

http://www.bitdefender.com/KB323-en--cevakrnl.xmd-vulnerability.html
Comment 1 Andrej Kacian (RETIRED) gentoo-dev 2006-12-25 07:50:50 UTC
I wonder why haven't I noticed this before. Quoting the URL above:

"An update has been issued on August 29,2006 to solve this vulnerability. The update has been delivered immediately to all BitDefender users through regular automatic update mechanism, so no user action is required."

Thus, there's no need for a version bump, as this has been fixed for every user who regularly updates via "bdc --update", as cevakrnl.xmd file is one of those being updated this way.

I will be adding 7.1 later today, just after I figure out what to do with a file collision that happens with this version. It's up to you guys if you want to close this bug by having 7.1 added (since cevakrnl.xmd shipped with it is fixed).
Comment 2 Andrej Kacian (RETIRED) gentoo-dev 2007-01-01 11:25:37 UTC
Just an update - I haven't found a good way to handle collision-protect for 7.1. It is in the tree, but masked. Perhaps someone can help me out here?

To reproduce the issue at hand, merge 7.0.1-r1, issue "bdc --update" and merge 7.1 (after unmasking it) with FEATURES="collision-protect"
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-01-06 12:23:35 UTC
Adding herd to get some response.
Comment 4 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-12 22:21:32 UTC
Antivirus team, please advise or we will have to take some nasty decision like a temporary masking GLSA or so :(
Thanks in advance.
Comment 5 Andrej Kacian (RETIRED) gentoo-dev 2007-01-13 01:10:41 UTC
I'm afraid I'm the only one regularly active on antivirus team, and I'm out of ideas how to handle bitdefender-console update without file collisions.

7.1 is in the tree, package.masked. To reproduce the trouble I'm having, merge 7.0.1-r1, update malware database with "bdc --update", and update to 7.1 with FEATURES="collision-protect".

BTW, I repeat that anyone who does "bdc --update" with 7.0.1 (or earlier) gets updated and non-vulnerable cevakrnl.xmd file.
Comment 6 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-13 20:54:23 UTC
> BTW, I repeat that anyone who does "bdc --update" with 7.0.1 (or earlier) gets
> updated and non-vulnerable cevakrnl.xmd file.


Thanks for all your answers Ticho. Unfortunately i can't help you on the collision issue.

Perhaps we could emit a GLSA telling to do a "bdc --update", but i really hope that our bitdefender-console users have already done that at least once since august.

So i propose to close that bug as invalid. Security team, please comment. (I'll close the bug as invalid within 7 days without any anwser.)
Comment 7 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-03-03 13:25:36 UTC
obsolete and invalid (considering the Gentoo Security scope, not anti-virus scope) as said earlier.

Feel free to reopen if you disagree.
Comment 8 Andrej Kacian (RETIRED) gentoo-dev 2007-04-08 22:58:32 UTC
Just for reference, 7.1 is now unmasked in the tree, after working around the collision issue.