Bug 83496 (CVE-2005-0605) - VUL-0: CVE-2005-0605: openmotif is affected by XPM bug CAN-2005-0605
Summary: VUL-0: CVE-2005-0605: openmotif is affected by XPM bug CAN-2005-0605
Status: RESOLVED FIXED
Alias: CVE-2005-0605
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other All
: P5 - None : Normal
Target Milestone: ---
Assignee: Andreas Schwab
QA Contact: Security Team bot
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: CVE-2005-0605: CVSS v2 Base Score: 7....
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-12 12:42 UTC by Thomas Biege
Modified: 2021-11-04 16:09 UTC (History)
3 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
patchinfo-box.openmotif (488 bytes, application/octet-stream)
2005-05-12 12:58 UTC, Thomas Biege
Details
patchinfo.openmotif (485 bytes, application/octet-stream)
2005-05-12 12:59 UTC, Thomas Biege
Details
xpm-fix-for-682.diff (51.79 KB, patch)
2005-05-12 13:28 UTC, Thomas Biege
Details | Diff
/work/SRC/all/openmotif/openmotif-2.2.3-xpm.diff (8.49 KB, patch)
2005-06-07 10:08 UTC, Andreas Schwab
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2005-05-12 12:42:44 UTC
Hello Andreas,
OpenMotif is also affected by other bugs in XPM.
Have a look at Bug #65868 and
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0605

Patch: https://bugzilla.novell.com/attachment.cgi?id=28728
Comment 1 Thomas Biege 2005-05-12 12:50:50 UTC
 SM-Tracker-1154
Comment 2 Andreas Schwab 2005-05-12 12:53:17 UTC
You are not authorized to access bug #65868. 
Comment 3 Thomas Biege 2005-05-12 12:57:19 UTC
added you to CC
Comment 4 Thomas Biege 2005-05-12 12:58:48 UTC
Created attachment 36963 [details]
patchinfo-box.openmotif
Comment 5 Thomas Biege 2005-05-12 12:59:12 UTC
Created attachment 36964 [details]
patchinfo.openmotif
Comment 6 Marcus Meissner 2005-05-12 13:03:37 UTC
dont forget openmotify21-libs or so. 
Comment 7 Andreas Schwab 2005-05-12 13:06:50 UTC
There is no bug.  
Comment 8 Thomas Biege 2005-05-12 13:28:10 UTC
But just b/c there missed a earlier patch.
Comment 9 Thomas Biege 2005-05-12 13:28:59 UTC
Created attachment 36968 [details]
xpm-fix-for-682.diff
Comment 10 Thomas Biege 2005-05-12 14:22:46 UTC
Looks like htese are missing.
CAN-2004-0692, CAN-2004-0782, CAN-2004-0783, CAN-2004-0914, CAN-2005-0605
Comment 11 Andreas Schwab 2005-05-12 14:43:31 UTC
This patch contains many stupid things. 
Comment 12 Thomas Biege 2005-05-12 14:46:30 UTC
Which are?
Comment 13 Andreas Schwab 2005-05-13 13:23:51 UTC
Don't make a fool of yourself, this is complete BS. 
Comment 14 Thomas Biege 2005-05-13 15:01:09 UTC
Facts are always welcome... even on a friday afternoon.


Comment 15 Andreas Schwab 2005-05-13 15:04:40 UTC
I'm replacing the original xpm patch with something much better which won't 
have this bug. 
Comment 16 Thomas Biege 2005-05-13 15:13:22 UTC
Ok but please stop closing this bug all the time.
Comment 17 Andreas Schwab 2005-05-13 15:15:16 UTC
This bug does not exist in openmotif. period.   
Comment 18 Thomas Biege 2005-05-17 08:51:24 UTC
Why not? I thought you want to write a new patch and now it doesn't exist?
Comment 19 Andreas Schwab 2005-05-17 09:43:04 UTC
See above. 
Comment 20 Anja Stock 2005-05-31 14:48:40 UTC
I would appreciate if we can push this discussion to a senseful end. Any news on
this?
Comment 21 Thomas Biege 2005-06-02 13:04:40 UTC
Andreas,
can you attach your patch and reassign back to me please.
Comment 22 Andreas Schwab 2005-06-07 10:08:19 UTC
Created attachment 38735 [details]
/work/SRC/all/openmotif/openmotif-2.2.3-xpm.diff
Comment 23 Thomas Biege 2005-06-07 12:56:43 UTC
The patch you wrote includes line that are also needed in older version, not
just stable.

Additionally your patch is 1/6 of the size of the original patch
(xpm-fix-for-682.diff). Does the missing code not affect openmotif or is it just
BS (to use your words)?
Comment 24 Anja Stock 2005-08-05 10:19:51 UTC
Any news here?
Comment 25 Marcus Meissner 2005-08-15 12:25:38 UTC
we hope the fix in STABLE sufficient. 
 
 
Comment 26 Thomas Biege 2005-10-11 13:54:08 UTC
*** Bug 127552 has been marked as a duplicate of this bug. ***
Comment 27 Thomas Biege 2005-10-11 13:54:50 UTC
Looks that no magic was in place to remove the bugs...
Comment 28 Andreas Schwab 2005-10-11 14:22:23 UTC
Please explain. 
Comment 29 Thomas Biege 2005-10-11 15:38:21 UTC
looks like another problem
Comment 30 Thomas Biege 2009-10-13 21:23:23 UTC
CVE-2005-0605: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)