[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-18 Thread Launchpad Bug Tracker
This bug was fixed in the package clamav - 0.92.1~dfsg2-1.1ubuntu0.1

---
clamav (0.92.1~dfsg2-1.1ubuntu0.1) hardy-security; urgency=low

  * SECURITY UPDATE: fix possible invalid memory access
  * added  27_petite.c.dpatch: (LP: #238575)
- libclamav/petite.c: fix possible invalid memory access
  * References
CVE-2008-2713

 -- Leonel Nunez [EMAIL PROTECTED]   Mon, 09 Jun 2008 15:46:30
-0600

** Changed in: clamav (Ubuntu Hardy)
   Status: In Progress = Fix Released

** Changed in: clamav (Ubuntu Gutsy)
   Status: In Progress = Fix Released

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-18 Thread Launchpad Bug Tracker
This bug was fixed in the package clamav - 0.92.1~dfsg2-1.1~gutsy3

---
clamav (0.92.1~dfsg2-1.1~gutsy3) gutsy-security; urgency=low

  * SECURITY UPDATE: fix possible invalid memory access
  * added 27_petite.c.dpatch: (LP: #238575)
- libclamav/petite.c: fix possible invalid memory access
  * References
CVE-2008-2713

 -- Leonel Nunez [EMAIL PROTECTED]   Mon, 09 Jun 2008 12:10:04
-0600

** Changed in: clamav (Ubuntu Feisty)
   Status: In Progress = Fix Released

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-18 Thread Launchpad Bug Tracker
This bug was fixed in the package clamav - 0.92.1~dfsg2-1.1~feisty3

---
clamav (0.92.1~dfsg2-1.1~feisty3) feisty-security; urgency=low

  * SECURITY UPDATE: fix possible invalid memory access
  * added 27_petite.c.dpatch: (LP: #238575)
- libclamav/petite.c: fix possible invalid memory access
  * References
CVE-2008-2713

 -- Leonel Nunez [EMAIL PROTECTED]   Mon,  9 Jun 2008 13:07:42
-0600

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-18 Thread Scott Kitterman
** Changed in: clamav (Ubuntu Dapper)
   Status: In Progress = Fix Released

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-17 Thread Kees Cook
I've fixed up all the changelog entries to follow a more regular format,
e.g.:

  * SECURITY UPDATE: fix possible invalid memory access
  * added  27_petite.c.dpatch: (LP: #238575)
- libclamav/petite.c: fix possible invalid memory access
  * References
CVE-2008-2713

(And added the now-assigned CVE #)

Additionally, I cleaned up the version numbers (ubuntu0.1 for hardy, and
bump for the ~ versions, instead of adding ubuntu1)


** CVE added: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2713

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-17 Thread Kees Cook
Intrepid was fixed with the sync of 0.93.1

** Changed in: clamav (Ubuntu)
   Status: Triaged = Fix Released

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-10 Thread Scott Kitterman
I think they can just edit it before they upload it.

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-10 Thread Leonel Nunez
ok

in case they don't I can redo the diff

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Scott Kitterman
Attached diff for 0.92.1

** Attachment added: Diff for fix
   http://launchpadlibrarian.net/15148171/petite.patch

** Changed in: clamav (Ubuntu)
   Importance: Undecided = Medium
   Status: New = Triaged

** Changed in: clamav (Ubuntu Hardy)
   Importance: Undecided = Medium
 Assignee: (unassigned) = Leonel Nunez (leonelnunez)
   Status: New = In Progress

** Changed in: clamav (Ubuntu Gutsy)
   Importance: Undecided = Medium
 Assignee: (unassigned) = Leonel Nunez (leonelnunez)
   Status: New = In Progress

** Changed in: clamav (Ubuntu Feisty)
 Assignee: (unassigned) = Leonel Nunez (leonelnunez)
   Status: New = Triaged

** Changed in: clamav (Ubuntu Feisty)
   Status: Triaged = In Progress

** Changed in: clamav (Ubuntu Feisty)
   Importance: Undecided = Medium

** Changed in: clamav (Ubuntu Dapper)
   Importance: Undecided = Medium
 Assignee: (unassigned) = Leonel Nunez (leonelnunez)
   Status: New = In Progress

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Scott Kitterman
For Intrepid, we should just wait and get 0.93.1 from Debian when they
have it.

** This bug has been flagged as a security issue

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
Diff for gutsy  applies fine
builded with  pbuild  and installed  fine
tested  all working  fine


** Attachment added: Gutsy DebDiff
   http://launchpadlibrarian.net/15153417/gutsy.debdiff

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
Gutsy debdiff  missing   the  00list  entry for the new patch ...
working on it

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
Diff for gutsy applies fine
builded with pbuild and installed fine
tested all working fine

All checked  even  00list  ;)


** Attachment added: feisty.debdif
   http://launchpadlibrarian.net/15157057/feisty.debdif

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
Patch applied fine  builded  with pbuilder  all fine
installed and tested  all working fine 

** Attachment added: dapper.debdiff
   http://launchpadlibrarian.net/15158296/dapper.debdiff

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
This is the debdiff fixed with the 00list edited to include the  patch 
all builds, installs and works fine 

** Attachment added: gutsy.debdiff
   http://launchpadlibrarian.net/15158439/gutsy.debdiff

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
And this  is for hardy

Applies, builds, installs  and works  fine


** Attachment added: hardy.debdiff
   http://launchpadlibrarian.net/15160803/hardy.debdiff

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Scott Kitterman
I've also tested the hardy version on my test mail server with clamsmtp.

The patch is identical (except the revision number) for all of them, so
I think they are all good to go.

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Scott Kitterman
I would suggest changing the dapper revision from dapper3 to
dapper2ubuntu1 to be consistent with the others.

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 238575] Re: Possible invalid memory access in versions before 0.93.1

2008-06-09 Thread Leonel Nunez
Does this means That I should redo the diff with the change ??

-- 
Possible invalid memory access in versions before 0.93.1
https://bugs.launchpad.net/bugs/238575
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs