Bug 486052 (CVE-2009-0577)

Summary: CVE-2009-0577 cups-CVE-2008-3640.patch has been corrupted.
Product: [Other] Security Response Reporter: keishi.sonoda
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: low    
Version: unspecifiedCC: bressers, dkovalsk, kreilly, mjc
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-02-19 18:44:41 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 486101    
Bug Blocks:    

Description keishi.sonoda 2009-02-18 01:47:10 UTC
Description of problem:
rpmbuild cannot apply cups-CVE-2008-3640.patch due to the patch corruption.

Version-Release number of selected component (if applicable):
cups-1.1.17-13.3.54.src.rpm
cups-1.1.17-13.3.55.src.rpm

How reproducible:
always

Steps to Reproduce:
1. rpm -i cups-1.1.17-13.3.54.src.rpm
2. rpmbuild -bp /usr/src/redhat/SPEC/cups.spec
  
Actual results:
error: File /usr/src/redhat/SOURCES/cups-CVE-2008-3640.patch is smaller than 4 bytes

Expected results:
Unpack the sources and apply the patch.

Additional info:

Comment 1 Josh Bressers 2009-02-18 12:34:15 UTC
We will assign this issue CVE-2009-0577.

Comment 3 Mark J. Cox 2009-02-19 08:18:49 UTC
Thank you for reporting this issue.  We will produce a security update to address this for Red Hat Enterprise Linux 3.  Note that Red Hat Enterprise Linux 4 and 5 already contain the correct fix for CVE-2008-3640 and do not need to be updated.

Comment 4 Red Hat Product Security 2009-02-19 18:44:41 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2009-0308.html