<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20841</bug_id>
          
          <creation_ts>2009-07-21 15:51:24 +0400</creation_ts>
          <short_desc>Common Data Format CDF File Processing Vulnerabilities</short_desc>
          <delta_ts>2009-07-22 00:42:32 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>libcdf</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc>http://www.infigo.hr/en/in_focus/advisories/INFIGO-2009-07-09</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Vitaly Lipatov">lav</assigned_to>
          <cc>lav</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>95006</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-07-21 15:51:24 +0400</bug_when>
    <thetext>Various memory corruption vulnerabilities have been identified during a
security audit of the CDF library. The vulnerabilities exist in the code
processing CDF files.

The vendor has addressed vulnerabilities on 20.7.2009. with CDF
library version 3.3. New CDF library 3.3 has &apos;cdfvalidate&apos; module
that will validate CDF files for potential malformed values.

Vulnerability discovered by Leon Juranic &lt;leon.juranic@infigo.hr&gt;

Other links:
http://cdf.gsfc.nasa.gov/html/CDF_v330.html
http://secunia.com/advisories/35940</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95042</commentid>
    <comment_count>1</comment_count>
    <who name="Vitaly Lipatov">lav</who>
    <bug_when>2009-07-22 00:42:32 +0400</bug_when>
    <thetext>Версия 3.3 стала собирать только libcdf.so
вместо прежнего soname, пока не решил, что делать.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>