Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
Not eligible to see or edit group visibility for this bug.
View Bug Activity | Format For Printing | XML | Clone This Bug
A weakness has been reported in MLDonkey, which can be exploited by malicious people to bypass certain security restrictions. The weakness is caused due to MLDonkey loading "$MLDONKEY/web_infos/*" after activating the network modules. This may allow other peers to connect from blocked IP addresses for a short time span. The weakness is reported in versions prior to 2.9.0. Solution: Update to version 2.9.0.
setting status and cc'ing herd. net-p2p, are we okay to call arches for marking 2.9.0 stable? plese advise.
Yeah, go ahead :)
ok, here we go :) arches, please test and mark stable net-p2p/mldonkey-2.9.0. Target keywords are: "~alpha amd64 hppa ia64 ppc ~sparc x86"
ia64/x86 stable
Small comments about this problem: - for older versions of MLDonkey: an IP blocklist file can be loaded using option ip_blocking, this way the blocklist is loaded before network modules are started - its not easy to backport the patch to load web_infos/* before network modules are starting, so using 2.9.0 is advised as its a bug-fix release
amd64 stable
ppc stable
hppa, something wrong here?
Sorry about the delay. Stable on hppa.
This one is ready for GLSA decision. I vote NO.
Voting NO and closing. Feel free to reopen if you disagree.