Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 78384 - media-video/ati-gatos CAN-2005-0016 Arbitrary code execution
Summary: media-video/ati-gatos CAN-2005-0016 Arbitrary code execution
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-01-17 09:43 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-01-24 05:06 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-17 09:43:39 UTC
Erik Sj
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-17 09:43:39 UTC
Erik Sjölund discovered a buffer overflow in xatitv, one of the
programs in the gatos package, that is used to display video with
certain ATI video cards.  xatitv is installed setuid root in order to
gain direct access to the video hardware.
Comment 2 Chris White (RETIRED) gentoo-dev 2005-01-17 09:51:48 UTC
Lu_zero:

  I believe ati drivers are your walk in the park :).  Mind taking a look at this one?
Comment 3 Luca Barbato gentoo-dev 2005-01-18 23:25:50 UTC
I can't find many references about xatitv.

The gatos ebuild should just provide the driver. We don't even provide the suggested tcl/tk viewer AVview. Not sure if that advisor applies to us or is just Debian only. I'll do further research during the day.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-01-19 01:16:12 UTC
I remember there was another issue in the Debian gatos package some time ago and we finally discovered that it didn't apply to us (not same sources, no xatitv on our side). I remember fetching the Debian package source to check...

So please doublecheck that we were right last time to drop it, in which case we'll drop it again.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-01-24 05:06:30 UTC
Does not apply to us, much like the old DSA-509-1