Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 459456 - app-portage/deltup bundles vulnerable versions of bzip2
Summary: app-portage/deltup bundles vulnerable versions of bzip2
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-02-27 08:23 UTC by Michael Palimaka (kensington)
Modified: 2016-03-01 05:55 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Palimaka (kensington) gentoo-dev 2013-02-27 08:23:14 UTC
$ qlist deltup | grep bzip
/usr/bin/bzip2_1.0.3
/usr/bin/bzip2_1.0.2

I am preparing a revision bump that fixes this.
Comment 1 Michael Palimaka (kensington) gentoo-dev 2013-02-27 08:33:31 UTC
(In reply to comment #0)
> I am preparing a revision bump that fixes this.

Apparently this is necessary to reconstruct archives made with old versions, so I will hold off doing this for now.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-07-07 15:36:34 UTC
I've added 0.4.5-r1 to tree, which doesn't include bundled bzip2. Since this does drop backwards compatibility, I'd suggest adding a PMASK for 0.4.5 with a warning about the vulnerability, drop 0.4.4, and be done with it. @sec team: does that sound okay? Alternatively, we can just drop 0.4.5 as well and bye bye backwards compatibility.
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-07-20 12:14:34 UTC
Removed 0.4.4 and PMASKed 0.4.5. Is it okay to close this one now, or does it stay open as long as there is a vulnerable version in the tree?
Comment 4 Pacho Ramos gentoo-dev 2015-11-04 15:13:49 UTC
looks like no vulnerable versions are present in the tree for some time
Comment 5 Aaron Bauman (RETIRED) gentoo-dev 2016-02-21 11:03:50 UTC
Two stable versions in tree 0.4.5-r1 and 0.4.6.  Per previous comments this vulnerability has been mitigated.
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2016-03-01 05:55:55 UTC
No CVE present and issue has been mitigated.  Vulnerability existed in a different package.  GLSA Vote: No