Bug 671064 (CVE-2011-0433) - VUL-0: CVE-2011-0433: evince: More Evince overflows
Summary: VUL-0: CVE-2011-0433: evince: More Evince overflows
Status: RESOLVED FIXED
: 685572 (view as bug list)
Alias: CVE-2011-0433
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2011-02-25
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:11.2:38834 maint:relea...
Keywords:
Depends on:
Blocks: 685572
  Show dependency treegraph
 
Reported: 2011-02-10 20:15 UTC by Thomas Biege
Modified: 2017-07-03 07:23 UTC (History)
4 users (show)

See Also:
Found By: Development
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2011-02-10 20:15:19 UTC
Hi.
There is a security bug in package 'evince'.

This information is from 'vendor-sec'.

This bug is NOT PUBLIC.

There is no coordinated release date (CRD) set.

More information can be found here:
	https://bugzilla.gnome.org/show_bug.cgi?id=640923


Original posting:


----------  Weitergeleitete Nachricht  ----------

Betreff: [vendor-sec] More Evince overflows
Datum: Donnerstag, 10. Februar 2011, 16:54:23
Von: Ulrik Persson <ddefrostt@gmail.com>
An:  vendor-sec@lst.de

More Evince overflows:

https://bugzilla.gnome.org/show_bug.cgi?id=640923

// Ulrik
_______________________________________________
Vendor Security mailing list
Vendor Security@lst.de
https://www.lst.de/cgi-bin/mailman/listinfo/vendor-sec

-------------------------------------------------------------
Comment 1 Thomas Biege 2011-02-10 20:54:02 UTC
Well it is public. :)
Comment 2 Vincent Untz 2011-02-17 15:37:43 UTC
I've fixed it upstream.

Fix submitted for Factory/11.4 (sr#61628), 11.3 (sr#61626), 11.2 (sr#61625).

Scott, who should take care of this for SLE?
Comment 3 Vincent Untz 2011-02-17 15:49:31 UTC
Btw, feel free to send the link to the fix to vendor-sec: http://git.gnome.org/browse/evince/commit/?id=439c5070022eab6cef7266aab47f978058012c72
Comment 4 Scott Reeves 2011-02-18 07:18:47 UTC
I will take this one.
Comment 5 Swamp Workflow Management 2011-02-18 14:41:43 UTC
The SWAMPID for this issue is 38801.
This issue was rated as important.
Please submit fixed packages until 2011-02-25.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 6 Scott Reeves 2011-02-19 20:34:32 UTC
Submitted fix to SLED11 SP1 (request #10766 ) and SLED10 (request #10765)
Comment 7 Thomas Biege 2011-02-21 11:48:03 UTC
CVE-2011-0433
Comment 8 Ludwig Nussel 2011-03-04 16:48:03 UTC
Date: Fri, 4 Mar 2011 17:13:47 +0100
From: Tomas Hoger <thoger@redhat.com>
Subject: Re: [oss-security] Re: CVE request: More Evince overflows

[...]
There's an off-by-one in those fixes, as it's been pointed out to me.
So if you've not fixed yet, you may want to look at:
  https://bugzilla.gnome.org/show_bug.cgi?id=643882

-- 
Tomas Hoger / Red Hat Security Response Team
Comment 12 Scott Reeves 2011-03-16 21:55:17 UTC
I fixed them all while I was in here...

11.2 - request #64345
11.3 - request #64346
11.4 - request #64347

sle10 - request #11208
sle11 sp1 - request #11209

I proposed my patch for upstream inclusion on the bug as well.
Comment 13 Ludwig Nussel 2011-03-17 07:00:31 UTC
Thanks!

The single zero byte overflow on the heap is probably not security relevant so I'm not starting a new security update on 11.4. We can include the fix in future evince updates instead.
Comment 14 Swamp Workflow Management 2011-04-01 12:02:37 UTC
Update released for: evince, evince-debuginfo, evince-debugsource, evince-devel, evince-lang, nautilus-evince, nautilus-evince-debuginfo
Products:
openSUSE 11.2 (debug, i586, x86_64)
openSUSE 11.3 (debug, i586, x86_64)
Comment 15 Ludwig Nussel 2011-04-01 12:08:18 UTC
released
Comment 16 Swamp Workflow Management 2011-04-01 18:46:29 UTC
Update released for: evince, evince-debuginfo, evince-debugsource, evince-devel, evince-doc, evince-lang
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 17 Swamp Workflow Management 2011-04-01 19:00:08 UTC
Update released for: evince, evince-debuginfo
Products:
SLE-DESKTOP 10-SP3 (i386, x86_64)
SLE-SAP-APL 10-SP3 (x86_64)
SLE-SERVER 10-SP3 (i386, ia64, ppc, s390x, x86_64)
Comment 18 Swamp Workflow Management 2011-04-01 20:43:57 UTC
Update released for: evince, evince-debuginfo
Products:
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 19 Leonardo Chiquitto 2011-04-20 21:59:26 UTC
*** Bug 685572 has been marked as a duplicate of this bug. ***
Comment 20 Matthias Weckbecker 2012-04-19 10:42:32 UTC
According to Thomas' comment and upstream bugzilla this issue is public.