Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 445846 (CVE-2012-5621) - <net-voip/ekiga-4.0.0-r1 : DoS (CVE-2012-5621)
Summary: <net-voip/ekiga-4.0.0-r1 : DoS (CVE-2012-5621)
Status: RESOLVED FIXED
Alias: CVE-2012-5621
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: CVE-2013-1864
Blocks:
  Show dependency tree
 
Reported: 2012-12-03 19:45 UTC by Agostino Sarubbo
Modified: 2014-08-25 22:57 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-12-03 19:45:35 UTC
From $URL :

  a denial of service flaw was found in the way Ekiga,
a Gnome based SIP/H323 teleconferencing application,
processed information from certain OPAL connections
([certain] UTF-8 strings were not verified for validity
prior showing them). A remote attacker (other party with
a not UTF-8 valid name) could use this flaw to cause
ekiga executable crash.

Upstream bug report:
[1] https://bugzilla.gnome.org/show_bug.cgi?id=653009

Relevant upstream patch:
[2] http://git.gnome.org/browse/ekiga/commit/?id=7d09807257

References:
[3] http://ftp.gnome.org/pub/gnome/sources/ekiga/4.0/ekiga-4.0.0.news
[4] https://bugzilla.redhat.com/show_bug.cgi?id=883058
Comment 1 Jesus Rivero (RETIRED) gentoo-dev 2012-12-03 23:49:03 UTC
I just bumped net-voip/ekiga-4.0.0 which takes care of this bug from upstream.
Comment 2 Agostino Sarubbo gentoo-dev 2012-12-04 10:10:23 UTC
(In reply to comment #1)
> I just bumped net-voip/ekiga-4.0.0 which takes care of this bug from
> upstream.

Is ok to stabilize?
Comment 3 Jesus Rivero (RETIRED) gentoo-dev 2012-12-05 01:31:17 UTC
Upstream is stable and I just bumped ekiga-4.0.0-r1.
There is a bug regarding Qt which I still have to check, so I don't think this is, yet, OK for stabilization. I need some more time to test.
Comment 4 Michael Palimaka (kensington) gentoo-dev 2013-03-05 13:35:51 UTC
(In reply to comment #3)
> Upstream is stable and I just bumped ekiga-4.0.0-r1.
> There is a bug regarding Qt which I still have to check, so I don't think
> this is, yet, OK for stabilization. I need some more time to test.

Is the issue still present? Can I assist in testing?
Comment 5 Jesus Rivero (RETIRED) gentoo-dev 2013-03-27 14:50:54 UTC
Somehow I lost track of this bug. I'd say go ahead with stabilization, that Qt bug was a non-issue.
Comment 6 Agostino Sarubbo gentoo-dev 2013-03-28 15:46:51 UTC
Arches, please test and mark stable:
=net-voip/ekiga-4.0.0-r1
Target keywords : "alpha amd64 ia64 ppc ppc64 sparc x86"
Comment 7 Agostino Sarubbo gentoo-dev 2013-03-28 22:44:38 UTC
amd64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-03-28 22:46:23 UTC
x86 stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-03-30 09:38:55 UTC
ppc stable
Comment 10 Agostino Sarubbo gentoo-dev 2013-04-01 19:45:50 UTC
ia64 stable
Comment 11 Agostino Sarubbo gentoo-dev 2013-04-01 19:53:59 UTC
alpha stable
Comment 12 Agostino Sarubbo gentoo-dev 2013-04-05 18:12:50 UTC
ppc64 stable
Comment 13 Sergey Popov gentoo-dev 2013-09-04 06:32:28 UTC
Reverting whiteboard to B3 [stable] - sparc is in security-supported arches list, waiting for stabilization...
Comment 14 Raúl Porcel (RETIRED) gentoo-dev 2014-08-04 18:48:31 UTC
sparc stable
Comment 15 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-08-04 18:56:22 UTC
Cleanup, please!

GLSA vote: no
Comment 16 Tobias Heinlein (RETIRED) gentoo-dev 2014-08-04 19:34:46 UTC
NO too, keeping open for cleanup.
Comment 17 Yury German Gentoo Infrastructure gentoo-dev 2014-08-25 21:16:26 UTC
Maintainer(s), please drop the vulnerable version (3.2.7).
Comment 18 Chris Reffett (RETIRED) gentoo-dev Security 2014-08-25 22:57:51 UTC
Maintainer timeout, cleanup done, closing noglsa.