First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 105695
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 105695 depends on: Show dependency tree
Show dependency graph
Bug 105695 blocks: 105719

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-09-12 08:31 0000
It appears as if qt is using it's own version of zlib if the zlib USE flag is  
not set.  
  
From 3.3.5 Changelog: 
 
Added security patches for zlib: CAN-2005-1849, CAN-2005-2096

------- Comment #1 From Thierry Carrez (RETIRED) 2005-09-12 09:01:52 0000 -------
Hm. Let's say USE=-zlib is quite uncommon and rate this B2.

------- Comment #2 From Thierry Carrez (RETIRED) 2005-09-17 05:39:26 0000 -------
KDE team: your position on this, please.

------- Comment #3 From Caleb Tennis 2005-09-18 07:21:25 0000 -------
FYI: 3.3.5 is in portage now, as unstable.

------- Comment #4 From Thierry Carrez (RETIRED) 2005-09-18 09:35:32 0000 -------
Thanks Caleb. Is it a candidate for stable right now ?

------- Comment #5 From Gregorio Guidi (RETIRED) 2005-09-19 03:03:42 0000 -------
(In reply to comment #4) 
> Thanks Caleb. Is it a candidate for stable right now ? 
 
I think not, see bug 106402. 
 
I suggest to commit qt-3.3.4-r8, the only difference to -r7 being that it 
forces "-system-zlib" as a compilation option. 
qt-3.3.4-r7 was ready to go stable, so qt-3.3.4-r8 could go stable right now. 
 

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-09-19 03:40:39 0000 -------
Back to ebuild status, waiting for a suitable ebuild to mark stable.  

------- Comment #7 From Caleb Tennis 2005-09-19 05:15:37 0000 -------
#5 works for me. 

------- Comment #8 From Sune Kloppenborg Jeppesen 2005-09-19 05:58:57 0000 -------
Yeah it does for me as well if -r8 gets committed. 

------- Comment #9 From Caleb Tennis 2005-09-19 07:06:46 0000 -------
-r8 is committed, but not yet stable on any arches.  I don't see why it can't 
go stable right away, but I'd like one more opinion on the matter (greg?). 

------- Comment #10 From Gregorio Guidi (RETIRED) 2005-09-19 08:32:00 0000 -------
I agree that it can go stable right now. Actually I was going to propose -r7 
for stable just before this bug showed up. 
 

------- Comment #11 From Thierry Carrez (RETIRED) 2005-09-19 08:59:03 0000 -------
OK, let's go then: archs please test and mark 3.3.4-r8 stable
Target KEYWORDS="alpha amd64 hppa ia64 mips ppc ppc64 ~ppc-macos sparc x86"

------- Comment #12 From Marcus D. Hanwell 2005-09-19 10:39:28 0000 -------
This version also introduces a dep on ~dev-db/qt-unixODBC-3.3.4 which isn't 
currently stable on amd64 and has an open security bug against it (bug 105719) 
- advise on this please. 

------- Comment #13 From Caleb Tennis 2005-09-19 19:04:33 0000 -------
I've committed a patch to the qt-unixodbc ebuild that should fix the RUNPATH
problem.

------- Comment #14 From Markus Rothe 2005-09-19 21:15:09 0000 -------
stable on ppc64 

------- Comment #15 From Gustavo Zacarias (RETIRED) 2005-09-20 07:25:06 0000 -------
sparc stable (with qt-unixODBC-3.3.4-r1).

------- Comment #16 From Michael Hanselmann (hansmi) (RETIRED) 2005-09-20 10:27:13 0000 -------
Stable on hppa, ppc

------- Comment #17 From Marcus D. Hanwell 2005-09-20 11:42:42 0000 -------
Looks good - stable on amd64. 

------- Comment #18 From Fernando J. Pereda 2005-09-21 02:34:48 0000 -------
Looks ok on alpha.

------- Comment #19 From Mark Loeser 2005-09-21 18:43:01 0000 -------
Stable on x86

------- Comment #20 From Thierry Carrez (RETIRED) 2005-09-22 01:59:19 0000 -------
Common GLSA with the qt-unixodbc thing ?

------- Comment #21 From Sune Kloppenborg Jeppesen 2005-09-22 04:02:54 0000 -------
Let's do a common GLSA with qt. 

------- Comment #22 From Sune Kloppenborg Jeppesen 2005-09-22 04:06:29 0000 -------
with qt-unixodbc of course :-) 

------- Comment #23 From Sune Kloppenborg Jeppesen 2005-09-26 13:56:00 0000 -------
GLSA 200509-18  
  
ia64 and mips don't forget to mark stable to benifit from the GLSA. 

------- Comment #24 From Hardave Riar (RETIRED) 2005-09-28 18:37:05 0000 -------
Stable on mips.

First Last Prev Next    No search results available      Search page      Enter new bug