Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 230045 (CVE-2008-2955) - net-im/pidgin File transfer filename vulnerability, DoS (CVE-2008-{2927,2955,2956,2957})
Summary: net-im/pidgin File transfer filename vulnerability, DoS (CVE-2008-{2927,2955,...
Status: RESOLVED FIXED
Alias: CVE-2008-2955
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa]
Keywords:
: 229099 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-06-29 16:01 UTC by Robert Buchholz (RETIRED)
Modified: 2009-01-20 22:04 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-06-29 16:01:39 UTC
Issue 1:
http://marc.info/?l=bugtraq&m=121449329530282&w=4

Issues 2 and 3:
http://crisp.cs.du.edu/?q=ca2007-1
Comment 1 Olivier Crete (RETIRED) gentoo-dev 2008-07-02 04:19:20 UTC
err .. 2007-01 is for version 2.0.0.....

2.4.3 should be released soon according to upstream
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-07-02 07:53:42 UTC
That's correct, it has been reported for 2.0.0 -- but looking at the code in 2.4.2, the patches linked in the advisory never made it in. Was this fixed at another place?
Comment 3 Olivier Crete (RETIRED) gentoo-dev 2008-07-02 14:19:42 UTC
2955 seems fixed by 2.4.3 .. 2956 and 2957 don't seem to be
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-07-02 20:01:20 UTC
Arches, please test and mark stable:
=net-im/pidgin-2.4.3
Target keywords : "alpha amd64 hppa ia64 ppc sparc x86"
Comment 5 Olivier Crete (RETIRED) gentoo-dev 2008-07-02 20:02:48 UTC
*** Bug 229099 has been marked as a duplicate of this bug. ***
Comment 6 Ferris McCormick (RETIRED) gentoo-dev 2008-07-02 20:46:31 UTC
On sparc at least, I'm not sure this installs the pidgin executable unless you have USE=gtk?  Can anyone confirm?  Is this intentional?
Comment 7 Olivier Crete (RETIRED) gentoo-dev 2008-07-02 20:54:06 UTC
This is intentional, if you have neither the gtk nor ncurses use flags, then you only get libpurple (which is used by telepathy-haze for example).
Comment 8 Ferris McCormick (RETIRED) gentoo-dev 2008-07-02 21:22:53 UTC
Thanks for the information (although it seems strange.  Does it warn the user in this case (USE='-ncurses gtk')?  If so, I didn't see it; if not, it might be worth considering.)  I am used to having USE=tk work as an alternative to USE=gtk.

Sparc stable.
Comment 9 Thomas Anderson (tanderson) (RETIRED) gentoo-dev 2008-07-02 21:26:54 UTC
amd64 stable
Comment 10 Olivier Crete (RETIRED) gentoo-dev 2008-07-02 21:35:53 UTC
Err.. USE=tk is completely different from USE=gtk, but I agree its probably a good idea to add a warning
Comment 11 Olivier Crete (RETIRED) gentoo-dev 2008-07-02 21:36:32 UTC
actually, there is already an elog message when you do that..
Comment 12 Christian Faulhammer (RETIRED) gentoo-dev 2008-07-03 12:38:52 UTC
x86 stable, this is good for people using ICQ, too.
Comment 13 DEMAINE Benoît-Pierre, aka DoubleHP 2008-07-03 19:30:27 UTC
net-im/pidgin-2.4.3 is already stable (x86) in portage on mirors :) Every one can update :) (I hope this will fix MSN and ICQ problems)
Comment 14 Robert Buchholz (RETIRED) gentoo-dev 2008-07-03 20:33:16 UTC
(In reply to comment #3)
> 2955 seems fixed by 2.4.3

Did you research the code? I could find no indication in the ChangeLog.
Comment 15 Olivier Crete (RETIRED) gentoo-dev 2008-07-03 20:51:35 UTC
I believe these are the two relevant commits to 2955 in 2.4.3:
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/709ec9c29e9d76eebbded25061107ef0a2a2b148
http://developer.pidgin.im/viewmtn/revision/diff/e09d33c61a6e5a59bfc3a52a4370aadf0a90f254/with/c3831c9181f4f61b747321240086ee79e4a08fd8

But I see nothign in their tree about the two other CVEs... Did I mentin that viewmtn sucks balls?
Comment 16 DEMAINE Benoît-Pierre, aka DoubleHP 2008-07-03 23:29:33 UTC
I just emerged 2.4.3 ... I dont know if it fixes the mentioned security issue, but MSN now works again. I mean: this new version is now compatible with the update of most servers.
Comment 17 Jeroen Roovers (RETIRED) gentoo-dev 2008-07-04 00:02:34 UTC
Stable for HPPA.
Comment 18 Raúl Porcel (RETIRED) gentoo-dev 2008-07-04 15:25:04 UTC
alpha/ia64 stable
Comment 19 Tobias Scherbaum (RETIRED) gentoo-dev 2008-07-05 11:54:24 UTC
ppc stable
Comment 20 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-07-06 18:20:23 UTC
glsa request filed.
Comment 21 Robert Buchholz (RETIRED) gentoo-dev 2008-07-06 21:51:53 UTC
As pointed out in [1], the update fixes another issue, CVE-2008-2927 -- and not the MSN filename. So back to [ebuild].

[1] http://article.gmane.org/gmane.comp.security.oss.general/618
Comment 22 Robert Buchholz (RETIRED) gentoo-dev 2008-07-30 18:41:05 UTC
upstream bug for CVE-2008-2955
http://developer.pidgin.im/ticket/6246
Comment 23 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-09-25 21:33:49 UTC
(In reply to comment #22)
> upstream bug for CVE-2008-2955
> http://developer.pidgin.im/ticket/6246
> 

It's fixed upstream... so where are we now? Is this fix included in 2.5.1?
Comment 24 Robert Buchholz (RETIRED) gentoo-dev 2008-11-27 17:17:25 UTC
http://www.pidgin.im/news/security/ states:

CVE-2008-2957 was fixed in 2.5.0
CVE-2008-2955 was fixed in 2.4.3
CVE-2008-2927 was fixed in 2.4.3

It seems upstream does not consider CVE-2008-2956 an issue, as they have no bug report or similar. Since this would only lead to a client-side DoS, we might want to ignore it as well.
Comment 25 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-01-20 22:04:12 UTC
GLSA 200901-13, sorry for the delay.