torcs: new versions 1.3.3 and 1.3.2 with security fixes available severity: important

Bug #941619 reported by Mantas Kriaučiūnas
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
torcs (Debian)
Fix Released
Unknown
torcs (Ubuntu)
Fix Released
Medium
Unassigned
Precise
Invalid
Undecided
Unassigned

Bug Description

New Torcs game versions 1.3.3 and 1.3.2 with security fixes are available since 2012. Also there are lots of crash bugs in Ubuntu bug tracking system - new TORCS version shoud fix at least some of these bugs.

 See also CVE-2012-1189: buffer overflow security bug ( http://seclists.org/oss-sec/2012/q1/440 ): http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=660555
Debian maintainer told, that he will upgrade torcs package ASAP, see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=660516

Related branches

CVE References

Micah Gersten (micahg)
tags: added: upgrade-software-version
Changed in torcs (Debian):
status: Unknown → Confirmed
Changed in torcs (Debian):
status: Confirmed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in torcs (Ubuntu):
status: New → Confirmed
Revision history for this message
Scott Kitterman (kitterman) wrote :

Ack. Approved for 1.33-2 (not 1).

Changed in torcs (Ubuntu):
importance: Undecided → Medium
status: Confirmed → Triaged
Revision history for this message
Scott Kitterman (kitterman) wrote :

Setting back to New for sponsor review.

Changed in torcs (Ubuntu):
status: Triaged → New
Revision history for this message
Daniel Holbach (dholbach) wrote :

The package seems to fail to build for me on precise amd64:
...
rm -f debian/stamp-autotools
rmdir --ignore-fail-on-non-empty .
rmdir: failed to remove `.': Invalid argument
make: [makefile-clean] Error 1 (ignored)
dh_clean
rm -f debian/stamp-autotools-files
 dpkg-source -b torcs-1.3.3
dpkg-source: info: using source format `3.0 (quilt)'
dpkg-source: info: building torcs using existing ./torcs_1.3.3.orig.tar.bz2
dpkg-source: info: local changes detected, the modified files are:
 torcs-1.3.3/Make-config
 torcs-1.3.3/config.h
 torcs-1.3.3/src/doc/torcsdoc.conf
 torcs-1.3.3/src/linux/torcs
 torcs-1.3.3/src/tools/accc/accc
 torcs-1.3.3/src/tools/nfs2ac/nfs2ac
 torcs-1.3.3/src/tools/nfsperf/nfsperf
 torcs-1.3.3/src/tools/texmapper/texmapper
 torcs-1.3.3/src/tools/trackgen/trackgen
 torcs-1.3.3/stamp-h1
dpkg-source: error: aborting due to unexpected upstream changes, see /tmp/torcs_1.3.3-2.diff.PEUEBS
dpkg-source: info: you can integrate the local changes with dpkg-source --commit
dpkg-buildpackage: error: dpkg-source -b torcs-1.3.3 gave error exit status 2
E: Failed autobuilding of package
...

Revision history for this message
Oibaf (oibaf) wrote :

There are still some problems with debian package 1.3.3-2 :
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=664220

Revision history for this message
Daniel Holbach (dholbach) wrote :

The problem mentioned in the Debian bug seems to be unrelated to the build failure I mentioned.

For now I'll unsubscribe the ubuntu-sponsors team. If there's a fix available, please resubscribe.

Revision history for this message
Iain Lane (laney) wrote :

Unsubscribing the release team for the same reason. If this has a chance of making Precise, please resubscribe with the necessary freeze exception paperwork

 - build log
 - install + upgrade log
 - testing info

Revision history for this message
Jeremy Bícha (jbicha) wrote :

torcs 1.3.3-4 is in Ubuntu quantal but fails to build.

Changed in torcs (Ubuntu):
status: New → Fix Released
status: Fix Released → Confirmed
Revision history for this message
Oibaf (oibaf) wrote :

1.3.4, now at "-test1", should build, see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668514

Jeremy Bícha (jbicha)
Changed in torcs (Ubuntu):
status: Confirmed → Fix Released
status: Fix Released → Confirmed
Revision history for this message
Marcin Juszkiewicz (hrw) wrote :

This debdiff makes torcs buildable again.

Revision history for this message
Marcin Juszkiewicz (hrw) wrote :

Requested FFe in bug #1042752

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package torcs - 1.3.3-5ubuntu1

---------------
torcs (1.3.3-5ubuntu1) quantal; urgency=low

  * Link libmusicplayer.so with OpenAL to fix FTFBS (Debian: #668514) LP: #941619
 -- Marcin Juszkiewicz <email address hidden> Tue, 28 Aug 2012 11:56:07 +0000

Changed in torcs (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Oibaf (oibaf) wrote :

No one is going to fix it for precise.

Changed in torcs (Ubuntu Precise):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.