Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 118550 - kde-base/kdelibs: kjs heap based buffer overflow (CVE-2006-0019)
Summary: kde-base/kdelibs: kjs heap based buffer overflow (CVE-2006-0019)
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
Whiteboard: B2 [glsa] DerCorny
: 119728 (view as bug list)
Depends on:
Blocks: 119737
  Show dependency tree
Reported: 2006-01-10 09:55 UTC by Carsten Lohrke (RETIRED)
Modified: 2006-01-22 06:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---

post-3.4.3-kdelibs-kjs.diff (post-3.4.3-kdelibs-kjs.diff,1.53 KB, patch)
2006-01-17 12:01 UTC, Carsten Lohrke (RETIRED)
no flags Details | Diff
kdelibs-3.4.3-r1.ebuild (kdelibs-3.4.3-r1.ebuild,3.40 KB, text/plain)
2006-01-17 12:02 UTC, Carsten Lohrke (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2006-01-10 09:55:06 UTC
Quoting Dirk Mueller: 

>We're planning to release this advisory at the end of next week. It is 
>currently not publically known, treat it with care. 

1. Systems affected:

        KDE 3.2.0 up to including KDE 3.5.0

2. Overview:

        Maksim Orlovich discovered an incorrect bounds check in kjs,
        the Javascript interpreter engine used by Konqueror and other
        parts of KDE, that allows a heap based buffer overflow
        when decoding invalid utf8 encoded URI sequences.

3. Impact:

        Remotely supplied Javascript code can perform a heap overflow
        and crash the web browser or execute arbitrary code.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-01-10 10:14:52 UTC
carlo, as it seems you are also in the kde herd. Will you do the bumping or who should be added to CC to fix this?
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-10 10:31:07 UTC
I'll take care.
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-17 12:01:26 UTC
Created attachment 77368 [details, diff]
Comment 4 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-17 12:02:09 UTC
Created attachment 77369 [details]
Comment 5 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-17 12:08:04 UTC
cc'ing arch guys for testing and Chris as release coordinator. Advisory should be out end of the week, as long as it isn't don't spread the patch, please.
Comment 6 Chris Gianelloni (RETIRED) gentoo-dev 2006-01-17 12:21:51 UTC
How soon on this?  We are planning on doing the release snapshot on Friday (20060120).  This can be injected into the snapshot later, of course.  I'm just trying to get an idea of the timetable.
Comment 7 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2006-01-17 12:32:47 UTC
I'm no longer the security contact for hppa and ppc. Added KillerFox (hppa) and dertobi123 (ppc).
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-17 12:36:06 UTC
Chris AFAIK the end of the week is the best information I have.

Arch security liaisons please test and report back on this bug.
Comment 9 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-17 12:38:42 UTC
Missed alpha. :)

Chris: End of the week. I have no idea if the announcement will be released before or on the 20th or if they shove it on the next monday. That's why I cc'ed you.
Comment 10 René Nussbaumer (RETIRED) gentoo-dev 2006-01-17 13:09:27 UTC
Adding gmsoft, because he has allready kdelibs merged.
Comment 11 René Nussbaumer (RETIRED) gentoo-dev 2006-01-17 13:15:56 UTC
Looks good on hppa
Comment 12 Tobias Scherbaum (RETIRED) gentoo-dev 2006-01-18 08:17:46 UTC
Looks good on ppc.
Comment 13 Markus Rothe (RETIRED) gentoo-dev 2006-01-18 08:32:53 UTC
looks good on ppc64: compiles and runs fine. is there an testcase given anywhere?
Comment 14 Mark Loeser (RETIRED) gentoo-dev 2006-01-18 19:53:40 UTC
Seems fine on x86.
Comment 15 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2006-01-19 13:40:51 UTC
Looks good on alpha.
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-19 22:23:21 UTC
Please commit with the following stable keywords:

alpha, hppa, ppc, ppc64, x86

amd64 and sparc please test and mark stable.
Comment 17 Chris Gianelloni (RETIRED) gentoo-dev 2006-01-20 06:25:17 UTC
Removing myself from the list (I'm on x86).
Comment 18 Jason Wever (RETIRED) gentoo-dev 2006-01-20 06:28:01 UTC
sparc looks fine, please commit with a stable sparc keyword as well
Comment 19 Stefan Cornelius (RETIRED) gentoo-dev 2006-01-20 06:38:39 UTC
Would somebody actually commit this ebuild? And what about the other versions of kde in portage 3.4.1, 3.4.2 and 3.5.0? They seem to be affected but i cant find a new ebuild for them?
Comment 20 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-20 07:00:19 UTC

(In reply to comment #13)
> is there an testcase given anywhere?

Unfortunately not.

(In reply to comment #19)
> And what about the other versions of kde in portage 3.4.1, 3.4.2 and 3.5.0? 

KDE 3.5 is not stable, so it's not relevant for stable testing. I committed a new ebuild revision of course. Users of the stable tree have to use KDE 3.4.3.
Comment 21 Marcus D. Hanwell (RETIRED) gentoo-dev 2006-01-20 07:23:36 UTC
Stable on amd64 too.
Comment 22 Markus Rothe (RETIRED) gentoo-dev 2006-01-20 08:08:57 UTC
this was commited as stable on ppc64. removing us from CC.
Comment 23 Gustavo Zacarias (RETIRED) gentoo-dev 2006-01-20 11:03:22 UTC
Carlo did the commit for us, so we're off the CC.
Comment 24 Tavis Ormandy (RETIRED) gentoo-dev 2006-01-20 12:00:13 UTC
*** Bug 119728 has been marked as a duplicate of this bug. ***
Comment 25 René Nussbaumer (RETIRED) gentoo-dev 2006-01-20 14:02:45 UTC
Removed hppa from CC. Allready stable.
Comment 26 Chris Gianelloni (RETIRED) gentoo-dev 2006-01-20 14:10:11 UTC
x86 is already marked stable...
Comment 27 Tobias Scherbaum (RETIRED) gentoo-dev 2006-01-20 22:27:37 UTC
ppc already stable ...
Comment 28 Stefan Cornelius (RETIRED) gentoo-dev 2006-01-21 05:59:13 UTC
removing alpha from CC, they seem to be already stable in the ebuild - ready for glsa.
Comment 29 Marcelo Goes (RETIRED) gentoo-dev 2006-01-21 13:16:39 UTC
Just in time for slashdot... :-)
Comment 30 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-22 06:52:48 UTC
GLSA 200601-11