Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 96727 - app-crypt/heimdal buffer overflow
Summary: app-crypt/heimdal buffer overflow
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Other
: High major (vote)
Assignee: Gentoo Security
URL: http://www.pdc.kth.se/heimdal/advisor...
Whiteboard: B1 [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-06-21 13:03 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-06-29 19:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-21 13:03:53 UTC
The telnetd server program in Heimdal has buffer overflows in the function getterminaltype, which may lead to remote code execution. 

0.6.5 and 0.7 fixes this problem.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-21 13:07:57 UTC
kerberos please advise. 
Comment 2 Seemant Kulleen (RETIRED) gentoo-dev 2005-06-21 13:09:57 UTC
will fix, stay tuned
Comment 3 Seemant Kulleen (RETIRED) gentoo-dev 2005-06-21 14:35:15 UTC
ok, so the vulnerability is valid -- I have added 0.6.5 into portage, testing
for EVERYONE.  I will stable amd64 in about 12 hours or so -- arch teams, please
note very carefully:

The following packages need to go stable *at the same time* :

sys-fs/e2fsprogs (the one which rdeps on the next two)
sys-libs/ss
sys-libs/com_err
app-crypt/mit-krb5-1.4 (which probably means db-4.2, but let's talk about that,
if that's not an option).
Comment 4 Seemant Kulleen (RETIRED) gentoo-dev 2005-06-21 14:35:21 UTC
ok, so the vulnerability is valid -- I have added 0.6.5 into portage, testing
for EVERYONE.  I will stable amd64 in about 12 hours or so -- arch teams, please
note very carefully:

The following packages need to go stable *at the same time* :

sys-fs/e2fsprogs (the one which rdeps on the next two)
sys-libs/ss
sys-libs/com_err
app-crypt/mit-krb5-1.4 (which probably means db-4.2, but let's talk about that,
if that's not an option).
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-21 23:19:23 UTC
Arches please test and mark stable not only app-crypt/heimdal but all packages  
mentioned in comment #3.  
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-06-22 13:17:55 UTC
Stable on ppc.
Comment 7 Gustavo Zacarias (RETIRED) gentoo-dev 2005-06-23 11:07:10 UTC
I'm getting broken stuff all over the place with com_err.
For instance cvs is linked against libcom_err.so.3 and sys-libs/com_err-1.37
just provides libcom_err.so

Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-23 12:22:00 UTC
Back to ebuild status, unCC'ing arches. 
 
Seemant please advise. 
Comment 9 Seemant Kulleen (RETIRED) gentoo-dev 2005-06-24 06:24:42 UTC
revdep-rebuild after emerging libcom_err -- I will add a big fat note in the
ebuild's postinst to do so.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-24 07:40:07 UTC
Back to stable, arches please test and mark. 
Comment 11 Gustavo Zacarias (RETIRED) gentoo-dev 2005-06-24 13:31:55 UTC
Added einfo big fat warning to mit-krb5 too.
Fixed USE=krb4 for heimdal since it didn't build no matter the arch.
Now sparc stable.
Comment 12 Seemant Kulleen (RETIRED) gentoo-dev 2005-06-27 13:34:15 UTC
stable on x86 and amd64.  mips, hppa, ia64 and alpha: you guys are up!
Comment 13 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-06-27 14:09:21 UTC
Stable on hppa.
Comment 14 Bryan Østergaard (RETIRED) gentoo-dev 2005-06-28 16:12:10 UTC
Alpha + ia64 stable.
Comment 15 Stefan Cornelius (RETIRED) gentoo-dev 2005-06-28 16:53:20 UTC
all important arches marked stable, mips promised to follow in one or two days.
glsa is already drafted and reviewed, just needs sending.
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-06-29 06:13:27 UTC
Thx everyone. 
 
GLSA 200506-24 
 
mips please remember to mark stable to benifit from the GLSA. 
Comment 17 Joshua Kinard gentoo-dev 2005-06-29 19:29:04 UTC
mips stable.