|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-2550: evolution format string bugs | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Michael Schröder <mls> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Critical | ||
| Priority: | P2 - High | CC: | forgotten_XUuSKZKdWe, gnome-bugs, joe, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | All | ||
| Whiteboard: | CVE-2005-2550: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | evolution-data.zip | ||
|
Description
Ludwig Nussel
2005-08-08 12:58:02 UTC
Created attachment 45124 [details]
evolution-data.zip
I didn't check what's inside. be careful.
ping ... what distros are affected? please provide fixed packages for those... hello? this is a critical issue, please provide an answer and fixed packages ASAP. The patches provided in the advisory notification had long been committed into the CVS on the 5th of August. The fixes are already available in the evolution 2.3.7 package available on Beta 2. Marcus : What about prior SuSE releases that ship Evolution 2.2/2.0. How can I deliver updated packages towards them ? Krishnan : Can the QA verify the fixes and see if there are related cases missed by the advisory that need attention ? could someone please provide fixed packages? why is this not going forward? it is a critical, remote exploitable problem? Do we just have 1 GNOME packager here (sbrabec, who is on vacation)? As noted above, the fix has long been available since Beta 2. This was merely waiting for confirmation from the QA. Closing this bug resolved. wtf? According to the report old evolution versions are affected. So please follow the procedure described in #5 and submit fixed packages. CAN-2005-2549, CAN-2005-2550 (In reply to comment #9) > wtf? According to the report old evolution versions are affected. So please > follow the procedure described in #5 and submit fixed packages. > > CAN-2005-2549, CAN-2005-2550 Went through the page you pointed out - I am not familiar with this process since I have not submitted packages directly for SuSE before. For records, the fixes are already available upstream on the CVS on all stable branches corresponding to Evo 2.0, 2.2 and 2.4 branches. (The other versions that are marked are development snapshots from HEAD and hence are not 'release versions' of any distro.) The page refers to 'package maintainer' - not sure if this would be me (project maintainer) or if Gary Ekker who submits the gnome packages for SuSE. It also adds that the patchinfo files would be handled by security team, not the package maintainer. So, can this now be assigned to the security team or is something else expected from my side ? Kindly clarify the same. Would be happy to do the needful. I don't care about evolution cvs. We need packages in autobuild. Who submits them doesn't matter from the security-team's point of view. 'Patchinfo' is the metadata required for the maintenance process. We can create it as soon as "the package maintainer" tells us which packages exactly are affected in which distributions. (In reply to comment #11) > I don't care about evolution cvs. Well, I do. > We need packages in autobuild. Who submits > them doesn't matter from the security-team's point of view. I do not know 'how'.Hence, I asked. > > 'Patchinfo' is the metadata required for the maintenance process. We can > create it as soon as "the package maintainer" tells us which packages exactly > are affected in which distributions. Thanks for the information. The affected packages have been listed in my earlier comment. Requesting Gary Ekker to submit the packages as required. MaintenanceTracker started with SWAMPID=2202, available at https://swamp.suse.de/webswamp/swamp/template/DisplayWorkflow.vm/workflowid/2202 Packages submitted for 9.2, 9.3, sles9-sld. Gary, Packages are missing for 9.0 and 9.1. from above comments it is not clear to me... Is Evolution < 2.0 affected by this problem or not? The problem only occurs in evolution-1.5.0 and greater. This is not necessary for 9.0 and 9.1. Then the evolution.patch.9.0 is not necessary and we are all complete. mls, please checkin. updates released CVE-2005-2550: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) |