Summary: | mail-client/sylpheed[-claws]: LDIF importer buffer overflow (CVE-2005-3354) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Thierry Carrez (RETIRED) <koon> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | geneseto, genone, hattya, lzap, rockoo |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B2? [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Thierry Carrez (RETIRED)
2005-11-08 02:12:14 UTC
This is semi-public, meaning it's not been announced yet but can be found in upstream CVS. We are free to commit new releases to Portage. hattya: we should add the following fixed versions : sylpheed-2.0.4 (stable) sylpheed-2.1.6 (~/masked) genone: for sylpheed-claws, we might need to backport the fix for our 1.0.5 stable line, as only 1.9.100 is released to fix. These are the patches for sylpheed-claws : http://colino.net/sylpheed-claws-gtk2/getpatchset.php3?ver=1.9.99cvs13 http://colino.net/sylpheed-claws-gtk2/getpatchset.php3?ver=1.9.99cvs15 *** Bug 111872 has been marked as a duplicate of this bug. *** Now completely public, please patch. will do what I can at the weekend (I'm currently pretty busy during the week), hopefully the patch for 1.0.5 shouldn't be tricky. The 1.9 branch might take a bit longer as it also requires updated plugins (this is why .99 is still p.masked). Ok, committed a 1.0.5-r1 as ~arch and a p.masked 1.9.100 (due to broken plugins). *** Bug 112198 has been marked as a duplicate of this bug. *** Sylpheed 2.0.4 and 2.1.6 are in CVS. Sylpheed-claws-1.9.100 unmasked as of a few minutes ago. All that remains to do for -claws is marking 1.0.5-r1 stable. arches, please test and mark stable if possible: mail-client/sylpheed-2.0.4: target keywords: "alpha amd64 hppa ia64 ppc ~ppc64 sparc x86" mail-client/sylpheed-claws-1.0.5-r1: target keywords: "alpha amd64 ppc ppc64 sparc x86" marked both ppc64 stable. ppc and hppa done. SPARCy SPARC and the stable bunch marked both stable on alpha. x86 is feeling a bit of those good vibrations, too... sylpheed doesn't like it when you don't give true settings, it hangs when you try to set up an account for dev.g.o on port 143... it hangs and you have to kill it. however, 2.0.1 has the same behaviour, so this gets the amd64 keyword nevertheless. both marked stable on amd64 Thx everyone... GLSA 200511-13 ia64 should mark stable to benefit from GLSA |