Bug 83496 (CVE-2005-0605)

Summary: VUL-0: CVE-2005-0605: openmotif is affected by XPM bug CAN-2005-0605
Product: [Novell Products] SUSE Security Incidents Reporter: Thomas Biege <thomas>
Component: IncidentsAssignee: Andreas Schwab <schwab>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: ast, patch-request, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: All   
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0605
Whiteboard: CVE-2005-0605: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CVSSv2:NVD:CVE-2004-0692:5.0:(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: patchinfo-box.openmotif
patchinfo.openmotif
xpm-fix-for-682.diff
/work/SRC/all/openmotif/openmotif-2.2.3-xpm.diff

Description Thomas Biege 2005-05-12 12:42:44 UTC
Hello Andreas,
OpenMotif is also affected by other bugs in XPM.
Have a look at Bug #65868 and
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0605

Patch: https://bugzilla.novell.com/attachment.cgi?id=28728
Comment 1 Thomas Biege 2005-05-12 12:50:50 UTC
 SM-Tracker-1154
Comment 2 Andreas Schwab 2005-05-12 12:53:17 UTC
You are not authorized to access bug #65868. 
Comment 3 Thomas Biege 2005-05-12 12:57:19 UTC
added you to CC
Comment 4 Thomas Biege 2005-05-12 12:58:48 UTC
Created attachment 36963 [details]
patchinfo-box.openmotif
Comment 5 Thomas Biege 2005-05-12 12:59:12 UTC
Created attachment 36964 [details]
patchinfo.openmotif
Comment 6 Marcus Meissner 2005-05-12 13:03:37 UTC
dont forget openmotify21-libs or so. 
Comment 7 Andreas Schwab 2005-05-12 13:06:50 UTC
There is no bug.  
Comment 8 Thomas Biege 2005-05-12 13:28:10 UTC
But just b/c there missed a earlier patch.
Comment 9 Thomas Biege 2005-05-12 13:28:59 UTC
Created attachment 36968 [details]
xpm-fix-for-682.diff
Comment 10 Thomas Biege 2005-05-12 14:22:46 UTC
Looks like htese are missing.
CAN-2004-0692, CAN-2004-0782, CAN-2004-0783, CAN-2004-0914, CAN-2005-0605
Comment 11 Andreas Schwab 2005-05-12 14:43:31 UTC
This patch contains many stupid things. 
Comment 12 Thomas Biege 2005-05-12 14:46:30 UTC
Which are?
Comment 13 Andreas Schwab 2005-05-13 13:23:51 UTC
Don't make a fool of yourself, this is complete BS. 
Comment 14 Thomas Biege 2005-05-13 15:01:09 UTC
Facts are always welcome... even on a friday afternoon.


Comment 15 Andreas Schwab 2005-05-13 15:04:40 UTC
I'm replacing the original xpm patch with something much better which won't 
have this bug. 
Comment 16 Thomas Biege 2005-05-13 15:13:22 UTC
Ok but please stop closing this bug all the time.
Comment 17 Andreas Schwab 2005-05-13 15:15:16 UTC
This bug does not exist in openmotif. period.   
Comment 18 Thomas Biege 2005-05-17 08:51:24 UTC
Why not? I thought you want to write a new patch and now it doesn't exist?
Comment 19 Andreas Schwab 2005-05-17 09:43:04 UTC
See above. 
Comment 20 Anja Stock 2005-05-31 14:48:40 UTC
I would appreciate if we can push this discussion to a senseful end. Any news on
this?
Comment 21 Thomas Biege 2005-06-02 13:04:40 UTC
Andreas,
can you attach your patch and reassign back to me please.
Comment 22 Andreas Schwab 2005-06-07 10:08:19 UTC
Created attachment 38735 [details]
/work/SRC/all/openmotif/openmotif-2.2.3-xpm.diff
Comment 23 Thomas Biege 2005-06-07 12:56:43 UTC
The patch you wrote includes line that are also needed in older version, not
just stable.

Additionally your patch is 1/6 of the size of the original patch
(xpm-fix-for-682.diff). Does the missing code not affect openmotif or is it just
BS (to use your words)?
Comment 24 Anja Stock 2005-08-05 10:19:51 UTC
Any news here?
Comment 25 Marcus Meissner 2005-08-15 12:25:38 UTC
we hope the fix in STABLE sufficient. 
 
 
Comment 26 Thomas Biege 2005-10-11 13:54:08 UTC
*** Bug 127552 has been marked as a duplicate of this bug. ***
Comment 27 Thomas Biege 2005-10-11 13:54:50 UTC
Looks that no magic was in place to remove the bugs...
Comment 28 Andreas Schwab 2005-10-11 14:22:23 UTC
Please explain. 
Comment 29 Thomas Biege 2005-10-11 15:38:21 UTC
looks like another problem
Comment 30 Thomas Biege 2009-10-13 21:23:23 UTC
CVE-2005-0605: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)