Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2006-01-12 Thread Martin Pitt
Hi Joey! Martin Schulze [2006-01-11 20:50 +0100]: > I'm attaching the current patch against the version in sarge. Please > let me know which version in sid fixes these problems. BTW, in order to keep a record of these duplicates, I recently created http://wiki.debian.org/EmbeddedCodeCopies M

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2006-01-12 Thread Frank Küster
Martin Schulze <[EMAIL PROTECTED]> wrote: > Frank Küster wrote: >> I'm currently preparing an upload of tetex-bin linked against libpoppler. > > I'm attaching the current patch against the version in sarge. Please > let me know which version in sid fixes these problems. None: Since the version i

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2006-01-11 Thread Martin Schulze
Frank Küster wrote: > I'm currently preparing an upload of tetex-bin linked against libpoppler. I'm attaching the current patch against the version in sarge. Please let me know which version in sid fixes these problems. The corresponding CVE names are: CVE IDs: CAN-2005-3191 CAN-2005-31

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-13 Thread Frank Küster
Martin Schulze <[EMAIL PROTECTED]> wrote: >> Am I correct that the other issues that Florian found are not addressed >> by any patch yet, and have not yet been widely published? Should I >> delay an upload to sid until this can be fixed, too? > > Which issues? *phear* Florian said that the new

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-12 Thread Martin Schulze
Hi Frank! Frank Küster wrote: > I looked at both, and it seems that Martin's does more. I'm speaking of > the patch attached to > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=342292;msg=136 > > It introduces limits.h and does the same we did for the xpdf patches at > the beginning of the ye

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-12 Thread Frank Küster
Martin Pitt <[EMAIL PROTECTED]> wrote: > Frank Küster [2005-12-11 13:27 +0100]: > >> Am I correct that the other issues that Florian found are not addressed >> by any patch yet, and have not yet been widely published? Should I >> delay an upload to sid until this can be fixed, too? > > Hm, I'm no

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-11 Thread Martin Pitt
Hi! Frank Küster [2005-12-11 13:27 +0100]: > >> Did you see Martin Pitt's "enhanced" patch - do both address the same > >> problems? > > > > The appendix removes the douplette Martin found, so yes. > > I looked at both, and it seems that Martin's does more. I'm speaking of > the patch attached t

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-11 Thread Frank Küster
Martin Schulze <[EMAIL PROTECTED]> wrote: > Frank Küster wrote: >> Hi Joey, >> >> Martin Schulze <[EMAIL PROTECTED]> wrote: >> >> > The original patch was not sufficient. I'm attaching the entire and the >> > incremental patch. Please apply the incremental patch to the version in >> > sid as w

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-09 Thread Martin Schulze
Frank Küster wrote: > Hi Joey, > > Martin Schulze <[EMAIL PROTECTED]> wrote: > > > The original patch was not sufficient. I'm attaching the entire and the > > incremental patch. Please apply the incremental patch to the version in > > sid as well. > > Did you see Martin Pitt's "enhanced" patch

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-09 Thread Frank Küster
Hi Joey, Martin Schulze <[EMAIL PROTECTED]> wrote: > The original patch was not sufficient. I'm attaching the entire and the > incremental patch. Please apply the incremental patch to the version in > sid as well. Did you see Martin Pitt's "enhanced" patch - do both address the same problems?

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-09 Thread Martin Schulze
Frank Küster wrote: > The upstream patch applies cleanly to xpdf/Stream.{cc,h} in sarge, but > JPXStream.cc does not exist. But the functions might still be defined > elsewhere. > > The patch does not apply cleanly, except for Stream.h, in woody, but at > least one affected line in Stream.cc *doe

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-07 Thread Frank Küster
found 342292 2.0.2-30 found 342292 2.0.2-31 found 342292 1.0.7+20011202-7.3 thanks The upstream patch applies cleanly to xpdf/Stream.{cc,h} in sarge, but JPXStream.cc does not exist. But the functions might still be defined elsewhere. The patch does not apply cleanly, except for Stream.h, in woo

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-07 Thread Frank Küster
Dear security team, Moritz Muehlenhoff <[EMAIL PROTECTED]> wrote: > Package: tetex-bin > Version: 3.0-10.1 > Severity: grave > Tags: security > Justification: user security hole > > Multiple exploitable security problems have been found in xpdf, which are > all present in tetex-bin's embedded xpd

Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

2005-12-06 Thread Moritz Muehlenhoff
Package: tetex-bin Version: 3.0-10.1 Severity: grave Tags: security Justification: user security hole Multiple exploitable security problems have been found in xpdf, which are all present in tetex-bin's embedded xpdf copy as well: Multiple Vendor xpdf DCTStream Baseline Heap Overflow Vulnerabilit