First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 135970
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
arts-3.5.3.diff arts-3.5.3.diff patch Sune Kloppenborg Jeppesen 2006-06-07 12:23 0000 946 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 135970 depends on: Show dependency tree
Bug 135970 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-06-07 12:22 0000
Dirk Mueller from KDE reports:

The vixie cron vulnerability also exists in several places.

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-06-07 12:23:50 0000 -------
Created an attachment (id=88621) [edit]
arts-3.5.3.diff

------- Comment #2 From Sune Kloppenborg Jeppesen 2006-06-07 12:27:58 0000 -------
Carlo please attach an updated ebuild. Do not commit anything to Portage yet.

------- Comment #3 From Carsten Lohrke 2006-06-09 08:10:19 0000 -------
Nice one... Public disclosure is 2006-06-15 together with a kdm symlink attack
vulnerability fix. Is there another hidden bug about it or should I open one? 

Will prepare the fixes late this evening or tomorrow.

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-06-09 08:27:30 0000 -------
Changing whiteboard to SEMI-PUBLIC as the general issue is already public.

Carlo up to you wether we should test the ebuild on this bug or commit direct
to Portage (with only the bug number mentioned in the ChangeLog).

------- Comment #5 From Carsten Lohrke 2006-06-11 06:35:41 0000 -------
arts-3.4.3-r1.ebuild
arts-3.5.2-r1.ebuild


I'm not sure who is responsible for KDE security bumps, but these are the
ebuilds, which need to go stable. 


Sune: Sorry that I'm later than predicted. Changed kde eclasses and fought with
repoman acting very weird.

------- Comment #6 From Stefan Cornelius (RETIRED) 2006-06-11 06:43:19 0000 -------
arches, please test if this is stable and report back. Altough this is set as
semi-public, better dont commit anything yet. Thanks

------- Comment #7 From Gustavo Zacarias (RETIRED) 2006-06-12 06:51:18 0000 -------
Passing on to weeve, he's our kde mofo and i'm not feeling quite well yet.

------- Comment #8 From Carsten Lohrke 2006-06-12 08:21:57 0000 -------
(In reply to comment #6)
> arches, please test if this is stable and report back. Altough this is set as
> semi-public, better dont commit anything yet. Thanks

Hu? I committed patch and ebuilds so everyone can read it. The patch is in KDE
svn, so everyone can read it. It would be careless not to mark the ebuilds
stable asap.

------- Comment #9 From Sune Kloppenborg Jeppesen 2006-06-12 08:25:31 0000 -------
Please test and MARK stable, this ain't no security drill so please just mark
stable in the tree.

------- Comment #10 From Markus Rothe 2006-06-12 11:09:54 0000 -------
stable on ppc64

@security: remove security liasons and add archs to CC?

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-06-12 11:35:17 0000 -------
It's still semi public, so we cannot add arches until it is completely opened.

------- Comment #12 From Jason Wever (RETIRED) 2006-06-13 19:32:40 0000 -------
SPARC is good here (or as good as arts ever gets).

------- Comment #13 From Tobias Scherbaum 2006-06-14 02:13:24 0000 -------
ppc stable

------- Comment #14 From Carsten Lohrke 2006-06-14 06:53:10 0000 -------
(In reply to comment #13)
> ppc stable
> 

You missed arts-3.4.3-r1

------- Comment #15 From Jason Wever (RETIRED) 2006-06-14 08:43:36 0000 -------
Based on comment #6, I have not touched the SPARC keywords from what they were
when the ebuilds entered the tree.  Do you folks want to work this like the kdm
bug or would you like the arch maestros to keyword the ebuilds?

------- Comment #16 From Sune Kloppenborg Jeppesen 2006-06-14 09:04:23 0000 -------
Jason please commit, we work directly in the tree on this one (see comment #9).

------- Comment #17 From Jason Wever (RETIRED) 2006-06-14 09:17:37 0000 -------
Ah missed that one.  Thanks for the pointer :)

SPARC is now stable.

------- Comment #18 From Tobias Scherbaum 2006-06-14 11:16:15 0000 -------
(In reply to comment #14)
> (In reply to comment #13)
> > ppc stable
> > 
> 
> You missed arts-3.4.3-r1

Oops ;) arts-3.4.3-r1 also ppc stable :)

------- Comment #19 From Carsten Lohrke 2006-06-14 11:44:51 0000 -------
Announcement is out, so the bug can be opened and arches cc'ed.

------- Comment #20 From Sune Kloppenborg Jeppesen 2006-06-14 12:30:55 0000 -------
Arches please test and mark stable.

------- Comment #21 From Thomas Cort (RETIRED) 2006-06-15 09:17:29 0000 -------
arts-3.4.3-r1 and arts-3.5.2-r1 stable on alpha and amd64.

------- Comment #22 From René Nussbaumer 2006-06-17 03:50:23 0000 -------
stable on hppa

------- Comment #23 From Carsten Lohrke 2006-06-17 05:02:56 0000 -------
Didn't want to wait forever on second pair of eyes. Stable on x86.

------- Comment #24 From Sune Kloppenborg Jeppesen 2006-06-17 06:18:14 0000 -------
Thx Carsten.

Ready for GLSA.

Security please review draft.

------- Comment #25 From Sune Kloppenborg Jeppesen 2006-06-22 13:04:31 0000 -------
GLSA 200606-22

ia64 don't forget to mark stable to benifit from the GLSA.

First Last Prev Next    No search results available      Search page      Enter new bug