Summary: | net-misc/curl <=7.15.0 malformed URL string buffer overflow | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Chris White (RETIRED) <chriswhite> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | akorthaus, bugreports, dragonheart, liquidx |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.hardened-php.net/advisory_242005.109.html | ||
Whiteboard: | B2? [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Chris White (RETIRED)
![]() Alastair please advise and patch as necessary. *** Bug 114729 has been marked as a duplicate of this bug. *** advisory from author: http://curl.haxx.se/docs/adv_20051207.html curl-7.15.1.ebuild added dev-python/pycurl-7.15.1 not added yet - no upstream version. please watch out for bug 100616 curl_off_t... configure: error: cannot compute sizeof (curl_off_t) and bug 111555 (self test errors - 253 and 255 failed for me but they failed in previous version too) curl-7.15.1 stable on ppc64. waiting for dev-python/pycurl-7.15.1 to be fixed before removing from CC. ppc, hppa done Forgot about pycurl Did alpha for net-misc/curl, waiting for dev-python/pycurl to be fixed. Cheers, Ferdy sparc stable. i can assume we'll be recalled when pycurl is in, so CC removing us to avoid noise (and maybe it'll even be on another bug!). Yes, it will be another bug for pycurl. Opening it right now. Removing stable arches, pycurl will be handled at bug 115524. amd64 done. stable on x86 GLSA 200512-09 arm ia64 mips s390 should probably mark stable to benefit from GLSA mips stable. What about other packages which ship with their own version of libcurl? According to http://www.heise.de/newsticker/meldung/70926 (sorry, German only) the official OpenOffice 2.01 builds are vulnerable, which affects app-office/openoffice-bin-2.01. Furthermore also app-text/acroread-7.0.1.1 ships with an old version of libcurl and might be affected as well. There is a new bug for OpenOffice 2.0.2 (bug #126433). Not sure about Acrobat Reader atm, but the latest stable version in portage is 7.0.5-r2 and i currently cant find any info that this version is vulnerable. |