Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 135970 - kde-base/arts Unchecked set*uid() calls (CVE-2006-2916)
Summary: kde-base/arts Unchecked set*uid() calls (CVE-2006-2916)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.kde.org/info/security/advi...
Whiteboard: A2 [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-07 12:22 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2006-10-15 05:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
arts-3.5.3.diff (arts-3.5.3.diff,946 bytes, patch)
2006-06-07 12:23 UTC, Sune Kloppenborg Jeppesen (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-07 12:22:34 UTC
Dirk Mueller from KDE reports:

The vixie cron vulnerability also exists in several places.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-07 12:23:50 UTC
Created attachment 88621 [details, diff]
arts-3.5.3.diff
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-07 12:27:58 UTC
Carlo please attach an updated ebuild. Do not commit anything to Portage yet.
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-09 08:10:19 UTC
Nice one... Public disclosure is 2006-06-15 together with a kdm symlink attack vulnerability fix. Is there another hidden bug about it or should I open one? 

Will prepare the fixes late this evening or tomorrow.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-09 08:27:30 UTC
Changing whiteboard to SEMI-PUBLIC as the general issue is already public.

Carlo up to you wether we should test the ebuild on this bug or commit direct to Portage (with only the bug number mentioned in the ChangeLog).
Comment 5 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-11 06:35:41 UTC
arts-3.4.3-r1.ebuild
arts-3.5.2-r1.ebuild


I'm not sure who is responsible for KDE security bumps, but these are the ebuilds, which need to go stable. 


Sune: Sorry that I'm later than predicted. Changed kde eclasses and fought with repoman acting very weird.
Comment 6 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-11 06:43:19 UTC
arches, please test if this is stable and report back. Altough this is set as semi-public, better dont commit anything yet. Thanks
Comment 7 Gustavo Zacarias (RETIRED) gentoo-dev 2006-06-12 06:51:18 UTC
Passing on to weeve, he's our kde mofo and i'm not feeling quite well yet.
Comment 8 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-12 08:21:57 UTC
(In reply to comment #6)
> arches, please test if this is stable and report back. Altough this is set as
> semi-public, better dont commit anything yet. Thanks

Hu? I committed patch and ebuilds so everyone can read it. The patch is in KDE svn, so everyone can read it. It would be careless not to mark the ebuilds stable asap.
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-12 08:25:31 UTC
Please test and MARK stable, this ain't no security drill so please just mark stable in the tree.
Comment 10 Markus Rothe (RETIRED) gentoo-dev 2006-06-12 11:09:54 UTC
stable on ppc64

@security: remove security liasons and add archs to CC?
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-12 11:35:17 UTC
It's still semi public, so we cannot add arches until it is completely opened.
Comment 12 Jason Wever (RETIRED) gentoo-dev 2006-06-13 19:32:40 UTC
SPARC is good here (or as good as arts ever gets).
Comment 13 Tobias Scherbaum (RETIRED) gentoo-dev 2006-06-14 02:13:24 UTC
ppc stable
Comment 14 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-14 06:53:10 UTC
(In reply to comment #13)
> ppc stable
> 

You missed arts-3.4.3-r1
Comment 15 Jason Wever (RETIRED) gentoo-dev 2006-06-14 08:43:36 UTC
Based on comment #6, I have not touched the SPARC keywords from what they were when the ebuilds entered the tree.  Do you folks want to work this like the kdm bug or would you like the arch maestros to keyword the ebuilds?
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-14 09:04:23 UTC
Jason please commit, we work directly in the tree on this one (see comment #9).
Comment 17 Jason Wever (RETIRED) gentoo-dev 2006-06-14 09:17:37 UTC
Ah missed that one.  Thanks for the pointer :)

SPARC is now stable.
Comment 18 Tobias Scherbaum (RETIRED) gentoo-dev 2006-06-14 11:16:15 UTC
(In reply to comment #14)
> (In reply to comment #13)
> > ppc stable
> > 
> 
> You missed arts-3.4.3-r1

Oops ;) arts-3.4.3-r1 also ppc stable :)
Comment 19 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-14 11:44:51 UTC
Announcement is out, so the bug can be opened and arches cc'ed.
Comment 20 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-14 12:30:55 UTC
Arches please test and mark stable.
Comment 21 Thomas Cort (RETIRED) gentoo-dev 2006-06-15 09:17:29 UTC
arts-3.4.3-r1 and arts-3.5.2-r1 stable on alpha and amd64.
Comment 22 René Nussbaumer (RETIRED) gentoo-dev 2006-06-17 03:50:23 UTC
stable on hppa
Comment 23 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-17 05:02:56 UTC
Didn't want to wait forever on second pair of eyes. Stable on x86.
Comment 24 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-17 06:18:14 UTC
Thx Carsten.

Ready for GLSA.

Security please review draft.
Comment 25 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-22 13:04:31 UTC
GLSA 200606-22

ia64 don't forget to mark stable to benifit from the GLSA.