Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 437814 (CVE-2012-4507) - <mail-client/claws-mail-3.8.1-r2 : NULL pointer derefence while processing email content (CVE-2012-4507)
Summary: <mail-client/claws-mail-3.8.1-r2 : NULL pointer derefence while processing em...
Status: RESOLVED FIXED
Alias: CVE-2012-4507
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: http://permalink.gmane.org/gmane.comp...
Whiteboard: B3 [noglsa]
Keywords:
: 441346 (view as bug list)
Depends on:
Blocks:
 
Reported: 2012-10-10 09:48 UTC by Alexander Tsoy
Modified: 2012-12-16 21:53 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-10 21:50:06 UTC
Thanks for the report, Alexander.
Comment 2 Christian Faulhammer (RETIRED) gentoo-dev 2012-10-11 19:02:18 UTC
I wanted to get it stabilised anyway soon:

all:
=mail-client/claws-mail-3.8.1-r2

amd64/x86
=mail-client/claws-mail-address_keeper-1.0.6
=mail-client/claws-mail-archive-0.6.12
=mail-client/claws-mail-att-remover-1.0.14
=mail-client/claws-mail-attachwarner-0.2.24
=mail-client/claws-mail-clamd-3.5.4
=mail-client/claws-mail-fancy-0.9.16
=mail-client/claws-mail-fetchinfo-0.4.25
=mail-client/claws-mail-gdata-0.4
=mail-client/claws-mail-geolocation-0.0.8
=mail-client/claws-mail-mailmbox-1.14.7
=mail-client/claws-mail-notification-0.30
=mail-client/claws-mail-python-0.10
=mail-client/claws-mail-rssyl-0.33
=mail-client/claws-mail-spam_report-0.3.16
=mail-client/claws-mail-tnef_parse-0.3.13
=mail-client/claws-mail-vcalendar-2.0.13
=mail-client/clawsker-0.7.8

alpha
=mail-client/claws-mail-rssyl-0.33

ppc
=mail-client/claws-mail-mailmbox-1.14.7
=mail-client/claws-mail-notification-0.30
=mail-client/claws-mail-rssyl-0.33
=mail-client/claws-mail-vcalendar-2.0.13

ppc64
=mail-client/claws-mail-att-remover-1.0.14
=mail-client/claws-mail-fetchinfo-0.4.25
=mail-client/claws-mail-mailmbox-1.14.7
=mail-client/claws-mail-rssyl-0.33

sparc
=mail-client/claws-mail-mailmbox-1.14.7
Comment 3 Vicente Olivert Riera (RETIRED) gentoo-dev 2012-10-12 23:32:45 UTC
=mail-client/claws-mail-geolocation-0.0.8 depends on =media-libs/clutter-gtk-0.10.8, but that package fails to compile: bug 435164
I added it as a depend. If some dev is not agree with that, please, feel free to remove it.
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2012-10-14 18:11:29 UTC
Stable for HPPA.
Comment 5 Anthony Basile gentoo-dev 2012-10-16 03:15:17 UTC
stable ppc ppc64
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2012-10-21 19:15:43 UTC
Remvoving the blocker as I do not see as an obstacle to stabilisation on unaffected architectures. But thanks.
Comment 7 Agostino Sarubbo gentoo-dev 2012-10-21 22:24:07 UTC
(In reply to comment #6)
> Remvoving the blocker as I do not see as an obstacle to stabilisation on
> unaffected architectures. But thanks.

A bug, to be in "Depends on" place, can affect for example one architecture.

If you prefer we will wait alpha and sparc and add back the blocker ;)
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2012-10-22 21:14:25 UTC
(In reply to comment #7)
> (In reply to comment #6)
> > Remvoving the blocker as I do not see as an obstacle to stabilisation on
> > unaffected architectures. But thanks.
> 
> A bug, to be in "Depends on" place, can affect for example one architecture.
> 
> If you prefer we will wait alpha and sparc and add back the blocker ;)

 This is a build failure that is unrelated to Claws security flaw...I could live with having claws-mail-geolocation held back for a while, it is not crucial, but the rest can go to stable.
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2012-10-23 20:30:46 UTC
CVE-2012-4507 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4507):
  The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1
  allows remote attackers to cause a denial of service (NULL pointer
  dereference and crash) via a crafted email.
Comment 10 Agostino Sarubbo gentoo-dev 2012-10-24 10:00:24 UTC
amd64 stable
Comment 11 Tobias Klausmann (RETIRED) gentoo-dev 2012-10-27 13:00:22 UTC
Stable on alpha.
Comment 12 Andreas Schürch gentoo-dev 2012-10-31 18:54:37 UTC
x86 is mostly done, i only left claws-mail-geolocation for the moment as of bug 440646. I kept x86 in cc.
Comment 13 Christian Faulhammer (RETIRED) gentoo-dev 2012-11-04 16:18:39 UTC
*** Bug 441346 has been marked as a duplicate of this bug. ***
Comment 14 Christian Faulhammer (RETIRED) gentoo-dev 2012-11-04 16:30:15 UTC
(In reply to comment #12)
> x86 is mostly done, i only left claws-mail-geolocation for the moment as of
> bug 440646. I kept x86 in cc.

-geolocation will be removed.  Unccing x86.
Comment 15 Raúl Porcel (RETIRED) gentoo-dev 2012-11-11 16:34:52 UTC
sparc stable
Comment 16 Sean Amoss (RETIRED) gentoo-dev Security 2012-11-12 11:48:10 UTC
Thanks, everyone.

GLSA vote: no.
Comment 17 Stefan Behte (RETIRED) gentoo-dev Security 2012-12-16 21:53:05 UTC
Application DOS. Vote: no.
Closing noglsa.