Summary: | app-office/koffice-1.3.4 weak integer overflow vulnerability fix | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Pablo De Nápoli <pdenapo> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | kde |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.koffice.org/releases/1.3.4-release.php | ||
Whiteboard: | A2 [glsa] koon | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 69936 | ||
Bug Blocks: |
Description
Pablo De Nápoli
2004-10-31 07:53:52 UTC
Looks like the original patch introduced in GLSA 200410-30 and bug 68558 may not be sufficient... KDE team : We might have to repatch this :/ The reported link doesn't works for me. This one works ftp://ftp.kde.org/pub/kde/stable/koffice-1.3.4/src/patch/koffice_1_3_4_xpdf_security_integer_overflow.diff BTW I've noticed that in KDECVS a similar patch was applied also to kpdf, but didn't find any report: http://lists.kde.org/?l=kde-cvs&m=109895739822113&w=2 >> IT'S WRONG http://lists.kde.org/?l=kde-cvs&m=109895658125554&w=2 >> IT'S RIGHT BUT APPLIED ON THE UPPER ONE. Can't find/verify gpg signature. The patch looks good, though. <<< koffice-1.3.3-r2.ebuild <<< koffice-1.3.4-r1.ebuild Arch herds, I have to ask you again: Please mark either one of the above ebuilds stable. ppc64: Would be nice, if you would use the "second chance". I can dump the old ebuilds in one rush then. Stable on ppc. koffice-1.3.3-r2 stable on sparc 1.3.4-r1 stable on alpha. 1.3.4-r1 stable on amd64 1.3.4-r1 stable on ppc64 Looks the same as (still not public) bug 69662 to me. Patches are different, but I would say they patch the same thing. Can someone with access double-confirm this is a different issue ? Koon: Yes, it is. Koffice is fixed, kdegraphics fixes follow in a few minutes. Thanks Carsten for clarification. We'll probably group xpdf 64 bit GLSAs (or update the old xpdf one). Will be released as a 200410-30 update when bug 69936 will be done. GLSA 200410-30:02 update out |