Summary: | media-libs/libmikmod heap overflow in GT2's loadChunk (CVE-2006-3879) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sune Kloppenborg Jeppesen (RETIRED) <jaervosz> |
Component: | Auditing | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | normal | CC: | hiyuh.root, sound |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://aluigi.altervista.org/adv/lmmgt2ho-adv.txt | ||
Whiteboard: | B2? [] | ||
Package list: | Runtime testing required: | --- |
Description
Sune Kloppenborg Jeppesen (RETIRED)
2006-07-25 02:39:12 UTC
CCing sound herd for info Still unfixed upstream There still does not seem to be a fix available upstream and actually to me it seems like upstream is dead. Anyone got other news/suggestions here? btw... !rrdep mikmod no reverse rdepends info for mikmod !rrdep libmikmod media-libs/libmikmod <- dev-games/clanlib dev-games/crystalspace dev-games/crystalspace-cvs games-action/heroes games-arcade/methane games-engines/stratagus games-puzzle/ensemblist games-puzzle/fbg games-puzzle/gweled games-strategy/xscorch media-libs/sdl-mixer media-libs/sdl-sound media-plugins/gst-plugins-mikmod media-sound/ecasound media-sound/mikmod media-sound/mpd actually I don't see loaders/load_gt2.c in neither of the two versions that are in the tree, so it seems we are not affected by this Can someone confirm that? sound herd? The original advisory says "versions 2.x.x and all the others in which the GT2 file format isn't implemented are not vulnerable". This really looks like 3.1.11-r2 doesn't include GT2 format, so I think we can close this one. after another check, there's definitely no GT2 support in the versions we ship, so we're not affected. closing as invalid, feel free to reopen if you disagree. |