Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 181179 - sys-apps/file 4.21 - problems processing a file containing only a large number of LFs
Summary: sys-apps/file 4.21 - problems processing a file containing only a large numbe...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://marc.info/?l=amavis-user&m=118...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-06-07 08:58 UTC by Icebird2000
Modified: 2007-06-07 12:36 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Icebird2000 2007-06-07 08:58:14 UTC
+++ This bug was initially created as a clone of Bug #173368 +++

>>> quotation <<<
4. Additional information
An unrelated CVE-2007-2026 DoS vulnerability of a file(1) utility
linked with a POSIX regex(3) library on Linux systems (but not *BSD
systems) is still unresolved in file-4.21, because the offending
two lines in a file 'magic' were not removed by mistake, even though
their correct replacements were added.

The following two lines from a 'magic' file that comes with file(1)
version 4.21 need to be manually removed:

100 regex/c =^\\s*call\\s+rxfuncadd.*sysloadfu OS/2 REXX batch file text
100 regex/c =^\\s*say\ ['"] OS/2 REXX batch file text

>>> quotation <<<


Actual Results:  
can fix with the patch of file-4.20
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-07 11:45:48 UTC

*** This bug has been marked as a duplicate of bug 174217 ***
Comment 2 Icebird2000 2007-06-07 11:55:11 UTC
(In reply to comment #1)
> 
> *** This bug has been marked as a duplicate of bug 174217 ***
> 

Point 4 in the linked advisory (CVE-2007-2026) is not fixed with 4.21. 
this bugreport is for version >>>>4.21<<<< not 4.20 and the bug from 4.20 is also in 4.21, so please fix it.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-07 12:36:29 UTC
Sorry, didn't notice that it was not properly fixed in 4.21. Handling it on the original bug #174217.