First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 198053
Alias:
Product:
Component:
Status: RESOLVED
Resolution: INVALID
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Richard Freeman <rich0@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 198053 depends on: Show dependency tree
Bug 198053 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-11-04 13:33 0000
GLSA 200710-12 is listed as applying to media-libs/t1lib < 5.0.2-r1.

However, version 1.3.1 is still in portage and has numerous dependencies.

If it is vulnerable then it needs to be fixed.  If it is not vulnerable then
the GLSA should be patched so that it doesn't come up as a false alarm.

Do we need to add to the glsa?:
<unaffected range="lt">5.0</unaffected>


Reproducible: Always

------- Comment #1 From Sune Kloppenborg Jeppesen 2007-11-05 08:03:10 0000 -------
fonts please advise wether 1.3.1 is affected?

------- Comment #2 From Sune Kloppenborg Jeppesen 2007-11-07 20:13:18 0000 -------
The same code is present in t1lib-1.3.1. Do we have anything depending on the
old version?

------- Comment #3 From Ryan Hill 2007-11-08 04:34:48 0000 -------
No, it doesn't look like it.  I've masked it for removal.

dirtyepic@tycho ~ $ qgrep -N t1lib-1
app-misc/gfontview-0.5.0-r6:DEPEND=">=media-libs/t1lib-1.0.1
app-text/xdvik-22.40y-r2:DEPEND=">=media-libs/t1lib-1.3
media-gfx/swftools-0.7.0:DEPEND=">=media-libs/t1lib-1.3.1
media-gfx/swftools-0.8.0:DEPEND=">=media-libs/t1lib-1.3.1
media-gfx/swftools-0.8.1:DEPEND=">=media-libs/t1lib-1.3.1
media-libs/t1lib-1.3.1:# $Header:
/var/cvsroot/gentoo-x86/media-libs/t1lib/t1lib-1.3.1.ebuild,v 1.29 2007/01/05
08:35:17 flameeyes Exp $
sci-visualization/grace-5.1.20: >=media-libs/t1lib-1.3.1
sci-visualization/grace-5.1.21: >=media-libs/t1lib-1.3.1

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-11-08 06:43:02 0000 -------
Thanks Ryan and Richard.

I'll close this one as INVALID since we don't have a policy regarding older
vulnerable versions in the tree.

First Last Prev Next    No search results available      Search page      Enter new bug