Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 280064 - app-portage/deltup: bundles bzip2 1.0.2 and 1.0.3
Summary: app-portage/deltup: bundles bzip2 1.0.2 and 1.0.3
Status: RESOLVED LATER
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Stefan Schweizer (RETIRED)
URL: http://www.gentoo.org/proj/en/qa/asne...
Whiteboard:
Keywords:
Depends on: 246916
Blocks: bundled-libs
  Show dependency tree
 
Reported: 2009-08-02 15:54 UTC by Alex Legler (RETIRED)
Modified: 2009-08-06 17:59 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-02 15:54:58 UTC
+++ This bug was initially created as a clone of Bug #246916 +++

Comment 3 from the original bug. Still old versions in SRC_URI.

> Given this was left unfixed and it's currently building two bzip2 versions that
> should be pretty vulnerable (
> http://www.gentoo.org/security/en/glsa/glsa-200804-02.xml ), can we just drop
> this?
>
Comment 1 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2009-08-06 01:26:35 UTC
@security team: 

Can you tell me how you tell that this package builds vulnerable bzip2? Thanks.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-08-06 17:54:09 UTC
/var/tmp/portage/app-portage/deltup-0.4.4/image $ find -name bz*
./usr/bin/bzip2_1.0.2
./usr/bin/bzip2_1.0.3

The whole design of deltup with regards to security is broken. It expects you to have the exact version of bzip installed that the archive was created with (which seems to be bzip's fault). So it bundles 1.0.2 and 1.0.3 and depends on 1.0.5 (currently). See also bug 89475.

Now this is not a vulnerability in deltup until a bzip version it ships becomes vulnerable, and GLSA 200804-02 affects the old bzip copies. However since the impact of that GLSA is a Denial of Service, this is not an issue in deltup. If an attacker can control a delta mirror, they can deny service to deltup users anyway. If an attacker could leverage these issues to execute arbitrary code, it would be more of an issue (and this might happen in the future).

To sum it up:
- I'm going to close this bug as it is not an issue for the security team.
- I'd encourage you to consider unbundling the bzip2 copies, users will
  need to download full files for files compressed using an old bzip2 then
  (still better than keeping a time bomb around, IMO).
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-08-06 17:55:36 UTC
sorry, I did not realize this was not a bug assigned to security@

reopening
Comment 4 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2009-08-06 17:59:21 UTC
Thanks Robert for the explanation. Given this package's importance for dial-up users, I don't think it is wise to mask for removal. I will exchange an email or two with deltup upstream author.

So, the answer to comment #0 is no. Not at this time.