Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bugzilla DB migration completed. Please report issues to Infra team via email via infra@gentoo.org or IRC
Bug 75201 - app-text/gpdf is probably affected by new xpdf vuln
Summary: app-text/gpdf is probably affected by new xpdf vuln
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-12-21 09:07 UTC by Thierry Carrez (RETIRED)
Modified: 2006-03-23 19:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2004-12-21 09:07:46 UTC
gpdf includes xpdf code and therefore might be vulnerable to CAN-2004-1125.
Please see bug 75191 for the patch.
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2004-12-21 12:26:26 UTC
gpdf includes xpdf 3.00 with the vulnerable code

gnome herd, pls provide an updated ebuild with the patches from bug 75191
Comment 2 Joe McCann (RETIRED) gentoo-dev 2004-12-22 04:52:27 UTC
Added gpdf-2.8.1-r1 to the tree with gpdf-xpdf-CAN-2004-1125.patch. Thanks for the heads up.
Comment 3 Matthias Geerdsen (RETIRED) gentoo-dev 2004-12-22 07:12:11 UTC
thanks Joe

security, this seems ready for a GLSA, since maintainer has kept keywords

Maybe we can combine this with the other xpdf related bugs?
Comment 4 Joe McCann (RETIRED) gentoo-dev 2004-12-22 09:05:48 UTC
not all archs are stable yet, cc'ing them.
Comment 5 Gustavo Zacarias (RETIRED) gentoo-dev 2004-12-22 09:23:04 UTC
Disclaimer: careful with moving over stable keywords, it wouldn't be the first time it broke (recent example = php).
Ok, sparc stable.
Comment 6 Mike Gardiner (RETIRED) gentoo-dev 2004-12-22 17:31:36 UTC
PPC stable.
Comment 7 Dylan Carlson (RETIRED) gentoo-dev 2004-12-22 18:47:39 UTC
amd64 done
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2004-12-23 02:37:10 UTC
Back to [stable] status : not ready yet, still missing a necessary keyword (alpha).
Comment 9 Bryan Østergaard (RETIRED) gentoo-dev 2004-12-23 12:33:50 UTC
Stable on alpha.
Comment 10 Guy Martin (RETIRED) gentoo-dev 2004-12-28 04:49:48 UTC
Stable on hppa.
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2004-12-28 05:09:18 UTC
GLSA 200412-24
ia64, mips : please mark gpdf stable to benefit from GLSA
Comment 12 Hardave Riar (RETIRED) gentoo-dev 2004-12-29 21:57:08 UTC
Stable on mips.
Comment 13 Matthias Geerdsen (RETIRED) gentoo-dev 2005-01-07 08:07:23 UTC
btw, this was http://bugzilla.gnome.org/show_bug.cgi?id=162084

a fixed gpdf 2.8.2 is supposed to follow today