First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 106002
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Renat Lumpau <rl03@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 106002 depends on: Show dependency tree
Bug 106002 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-09-14 14:07 0000
From http://egroupware.org : 

News 12. Sep. + 16. Aug. 2005: Again new xmlrpc security fixes in release
1.0.0.009-2

The new 1.0.0.009-2 release contains the security fixes related to xmlrpc from
the 16. August 2005. Plus a new preventiv fix, which allows to enable or disable
(default) the xmlrpc and soap subsystem. With the 1.0.0.009-2 release all
package formats (incl. rpm's and signed packages) are avalible again.

We recommend everyone to update to this release asap. Download them here.

------- Comment #1 From Renat Lumpau 2005-09-14 14:09:46 0000 -------
egroupware-1.0.0.009_p2 in CVS.

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-09-14 21:56:02 0000 -------
Arches please test and mark stable. 
 
Not sure what they fixed this time though. 

------- Comment #3 From Thierry Carrez (RETIRED) 2005-09-15 01:09:31 0000 -------
"The new 1.0.0.009-2 release contains the security fixes related to xmlrpc from
the 16. August 2005. Plus a new preventiv fix, which allows to enable or disable
(default) the xmlrpc and soap subsystem."

So it contains the original fixes we already provided in 200508-14 + it disables
by default the xmlrpc and soap subsystems. This is not a new vulnerability.
Moving to default config... but we could invalidate the bug as well.

------- Comment #4 From Michael Hanselmann (hansmi) (RETIRED) 2005-09-15 10:25:44 0000 -------
Stable on ppc.

------- Comment #5 From Renat Lumpau 2005-09-15 16:27:55 0000 -------
Stable on x86

------- Comment #6 From Simon Stelling (RETIRED) 2005-09-17 02:36:25 0000 -------
amd64 done

------- Comment #7 From Bryan Østergaard (RETIRED) 2005-09-17 17:58:41 0000 -------
Stable on alpha.

------- Comment #8 From Jose Luis Rivero (yoswink) 2005-09-17 19:52:50 0000 -------
Emm a little note about all this process:

I was testing egroupware for alpha and saw some problems when i tried to compile it:

Calculating dependencies ...done!
>>> emerge (1 of 1) www-apps/egroupware-1.0.0.009_p2 to /
>>> md5 src_uri ;-) eGroupWare-1.0.0.009-2.tar.bz2

!!! ERROR: www-apps/egroupware-1.0.0.009_p2 failed.
!!! Function has_php, Line 213, Exitcode 1
!!! Unable to find an installed dev-lang/php package
!!! If you need support, post the topmost build error, NOT this status message.

In this version egroupware ebuild has changed the inherit section from eutils to
depend.php.

"require_php_with_use" depend.php's function use "has_php" and "has_php" use
dev-lang/php-* testing. dev-lang/php (currently) hasn't got any stable version
in any arch so ...

------- Comment #9 From Renat Lumpau 2005-09-17 21:22:09 0000 -------
hrm. i had checked with the php folks and was told that require_php_with_use is
the way to go. I guess for the time being we can comment out the require_...
stuff and drop the depend.php part. 

my dev machine is down atm, could someone else fix this?

------- Comment #10 From Bryan Østergaard (RETIRED) 2005-09-18 04:59:40 0000 -------
Removed alpha keyword again until the dev-lang/php issue is fixed.

------- Comment #11 From Renat Lumpau 2005-09-18 08:53:51 0000 -------
I've removed the depend.php inherit until dev-lang/php goes stable in early
October. 

------- Comment #12 From Jose Luis Rivero (yoswink) 2005-09-18 12:00:13 0000 -------
Don't you think we need to CC'ed arches again? 

They have marked an ebuild stable and, now, it has suffered some "heavy changes". 
I suppose they marked it stable due to *it works*, so, at least for me (as arch
tester) i wouldn't like to see an ebuild with my stable keyword after the
maintainer has done important changes.

Also reporting to them, we could see what kind of test they do and may help
people to fix their system (if needed), since the inherit depend.php was broken
and magically worked. This is what happened to kloeri who likes to
install/uninstall/downgrade/upgrade apache and php stuff due to his work as
apache lead ;)

------- Comment #13 From Renat Lumpau 2005-09-18 12:37:41 0000 -------
Arches - please take a look at the ebuild one more time.

The "heavy changes" amount to commenting out depend.php and replacing
require_php_with_use with einfo warnings.

------- Comment #14 From Bryan Østergaard (RETIRED) 2005-09-18 12:50:50 0000 -------
Alpha stable again.

------- Comment #15 From Michael Hanselmann (hansmi) (RETIRED) 2005-09-19 12:46:20 0000 -------
ppc's fine

------- Comment #16 From Simon Stelling (RETIRED) 2005-09-20 02:59:48 0000 -------
still seems to work fine

------- Comment #17 From Sune Kloppenborg Jeppesen 2005-09-20 23:42:10 0000 -------
Thx everyone. 

First Last Prev Next    No search results available      Search page      Enter new bug