Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 325577 (CVE-2010-1457) - <gnustep-base/gnustep-base-1.20.1: Multiple vulnerabilities (CVE-2010-{1457,1620})
Summary: <gnustep-base/gnustep-base-1.20.1: Multiple vulnerabilities (CVE-2010-{1457,1...
Status: RESOLVED FIXED
Alias: CVE-2010-1457
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: http://ftpmain.gnustep.org/pub/gnuste...
Whiteboard: B1 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-25 20:04 UTC by Stefan Behte (RETIRED)
Modified: 2014-01-20 09:10 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 20:04:48 UTC
CVE-2010-1457 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1457):
  Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local
  users to read arbitrary files via a (1) -c or (2) -a option, which
  prints file contents in an error message.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 20:06:48 UTC
Is 1.20.1 ready to go stable?
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 21:36:35 UTC
CVE-2010-1620 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1620):
  Integer overflow in the load_iface function in Tools/gdomap.c in
  gdomap in GNUstep Base before 1.20.0 might allow context-dependent
  attackers to execute arbitrary code via a (1) file or (2) socket that
  provides configuration data with many entries, leading to a
  heap-based buffer overflow.

Comment 3 Bernard Cafarelli gentoo-dev 2010-06-26 10:20:26 UTC
Well I had no problems myself (and no bugreports) on 1.20.*, so 1.20.1 can certainly go stable

This will require stabling of other gnustep-base/ packages though (stable gnustep-gui-0.16.0 does not build with gnustep-base-1.20).

Here is the list for the set of packages to go with 1.20:
- gnustep-base/gnustep-make-2.4.0 (amd64, ppc, ppc64, sparc, x86)
- gnustep-base/gnustep-base-1.20.1 (amd64, ppc, sparc, x86)
- gnustep-base/gnustep-gui-0.18.0 (amd64, ppc, sparc, x86)
- gnustep-base/gnustep-back-art-0.18.0 (amd64, ppc, sparc, x86)
- gnustep-base/gnustep-back-xlib-0.18.0 (amd64, ppc, sparc, x86)
- gnustep-base/gnustep-back-cairo-0.18.0 (amd64, x86)
and the virtual for the last 3: - virtual/gnustep-back-0.18.0 (amd64, ppc, sparc, x86)

Same comment as 1.20.1, I have seen no problems myself and no bugreports opened
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2010-06-26 13:20:08 UTC
Re-rating as per comment #2.
Comment 5 Tobias Heinlein (RETIRED) gentoo-dev 2010-06-26 13:22:35 UTC
(In reply to comment #3)
> Well I had no problems myself (and no bugreports) on 1.20.*, so 1.20.1 can
> certainly go stable
> 
> This will require stabling of other gnustep-base/ packages though (stable
> gnustep-gui-0.16.0 does not build with gnustep-base-1.20).

Thanks for the detailed response. Arches, please stabilise as outlined in comment #3.
Comment 6 Christoph Mende (RETIRED) gentoo-dev 2010-06-26 16:37:51 UTC
amd64 stable
Comment 7 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-06-27 13:58:50 UTC
x86 stable
Comment 8 Samuli Suominen (RETIRED) gentoo-dev 2010-07-05 11:19:30 UTC
ppc64 stable (for the only package listed for ppc64 here, gnustep-make)
Comment 9 Raúl Porcel (RETIRED) gentoo-dev 2010-07-08 18:06:50 UTC
sparc stable
Comment 10 Joe Jezak (RETIRED) gentoo-dev 2010-08-13 17:33:54 UTC
Marked ppc stable.
Comment 11 Bernard Cafarelli gentoo-dev 2010-08-20 12:33:45 UTC
All arches stable, previous stable versions removed from tree
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2011-01-02 03:24:57 UTC
GLSA Request Filed.
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2014-01-20 09:10:16 UTC
This issue was resolved and addressed in
 GLSA 201401-12 at http://security.gentoo.org/glsa/glsa-201401-12.xml
by GLSA coordinator Sergey Popov (pinkbyte).