Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 72681 - media-libs/imlib: Multiple imlib issues. (CAN-2004-1026)
Summary: media-libs/imlib: Multiple imlib issues. (CAN-2004-1026)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High major (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/bugzilla/...
Whiteboard: A2 [glsa] koon
Keywords:
Depends on:
Blocks:
 
Reported: 2004-11-27 16:52 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2004-12-06 07:58 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-27 16:52:40 UTC
FL uses an older version than we have in Portage, but we might be affected anyway.

Snipped from FL bug:

I've discovered more vulnerabilities in Imlib (1.9.13). In particular, it
appears to be affected by a variant of Chris Evans' libXpm flaw #1
(CAN-2004-0782, see http://scary.beasts.org/security/CESA-2004-003.txt). Look
at the attached image, it kills ee on my 7.3.
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2004-11-29 01:10:12 UTC
The patch in the RedHat bug is for .13, but seems to fix stuff present in .14 too.
Then there is this Fedora bug
https://bugzilla.fedora.us/show_bug.cgi?id=2051#c11
with patches provided by Pavel Kankovsky. The patch for .14 seems to be mainly the same as we have in portage atm, but someone might want to check out the patches for .13, which seem to patch stuff present in .14 too.
Comment 2 Matthias Geerdsen (RETIRED) gentoo-dev 2004-11-30 03:04:00 UTC
gnome team, please verify, advise and apply patches if appropriate

patches can be found in the two bug reports mentioned in the above comments
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2004-12-02 01:41:18 UTC
Could not reproduce this, but I don't know what really makes use of imlib...
Comment 4 foser (RETIRED) gentoo-dev 2004-12-02 05:55:03 UTC
gnome1 apps probably.
Comment 5 Carsten Lohrke (RETIRED) gentoo-dev 2004-12-03 16:45:02 UTC
>Could not reproduce this, but I don't know what really makes use of imlib...
>gnome1 apps probably.

a wide range of apps does:

x11-plugins/gkrellm-radio
x11-plugins/gkrellm-alltraxclock
x11-plugins/epplets
x11-plugins/gkrellmoon
x11-plugins/gkrellsun
x11-plugins/gkrellm-console
x11-plugins/gkrellm-mailwatch
x11-plugins/gkrellm-bfm
x11-plugins/gkrellmouse
x11-plugins/gkrellscore
x11-plugins/gkrellshoot
x11-libs/libast
x11-misc/bbrb
x11-misc/pogo
x11-misc/e16menuedit
x11-misc/idesk
x11-misc/wmakerconf
x11-misc/e16keyedit
www-client/w3m
www-client/w3mmee
www-client/w3m-m17n
games-strategy/freeciv
x11-terms/mlterm
app-admin/gkrellm
x11-themes/gtk-engines
x11-themes/qtpixmap
gnome-base/gnome-libs
app-i18n/minichinput
app-i18n/chinput
app-misc/dfm
app-misc/endeavour
kde-base/kdegraphics
mail-client/balsa
mail-client/sylpheed-claws
mail-client/sylpheed
media-gfx/iv
media-gfx/qiv
media-gfx/xzgv
media-gfx/frontline
media-gfx/digikam
media-gfx/gphoto
media-gfx/gimageview
net-irc/bitchx
net-www/amaya
media-libs/fnlib
net-im/amsn
net-im/gnophone
net-libs/jaimlib
games-board/eboard
app-office/magicpoint
x11-wm/fvwm
x11-wm/qvwm
x11-wm/xfce
x11-wm/icewm
x11-wm/sawfish
x11-wm/enlightenment
dev-lang/R
dev-lang/entity
dev-ruby/ruby-gdkimlib
dev-ruby/ruby-gnome
dev-python/pygtk
dev-python/gnome-python
app-editors/zoinks
media-sound/yconsole
media-video/kino
media-video/motioneye
media-video/camserv
app-sci/scigraphica
games-kids/lletters
games-kids/stickers
Comment 6 Joe McCann (RETIRED) gentoo-dev 2004-12-04 14:39:51 UTC
I have added imlib-1.9.14-r3 to cvs ( with the patch from https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=138516 ). That combined with our patch takes care of the overflow issues. Archs please test and mark stable.
Comment 7 Mike Doty (RETIRED) gentoo-dev 2004-12-04 15:23:39 UTC
stable on amd64
Comment 8 Jochen Maes (RETIRED) gentoo-dev 2004-12-05 00:36:35 UTC
stable on ppc
Comment 9 SpanKY gentoo-dev 2004-12-05 01:29:54 UTC
arm/hppa/ia64 stable
Comment 10 Markus Rothe (RETIRED) gentoo-dev 2004-12-05 01:31:21 UTC
stable on ppc64
Comment 11 SpanKY gentoo-dev 2004-12-05 01:32:39 UTC
err didnt mean to close
Comment 12 Ferris McCormick (RETIRED) gentoo-dev 2004-12-05 07:37:54 UTC
Stable for sparc.
Comment 13 Bryan Østergaard (RETIRED) gentoo-dev 2004-12-05 08:05:11 UTC
Stable on alpha.
Comment 14 Stephen Becker (RETIRED) gentoo-dev 2004-12-05 19:10:32 UTC
stable on mips
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2004-12-06 02:07:32 UTC
GLSA drafted
Comment 16 Thierry Carrez (RETIRED) gentoo-dev 2004-12-06 07:58:22 UTC
GLSA 200412-03