Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 271712 - =dev-libs/boost-1.33.1-r1 removal for GLSA 200802-08
Summary: =dev-libs/boost-1.33.1-r1 removal for GLSA 200802-08
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: C++ Team [disbanded]
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: glsa-removal
  Show dependency tree
 
Reported: 2009-05-29 13:41 UTC by Robert Buchholz (RETIRED)
Modified: 2009-12-11 18:40 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-05-29 13:41:21 UTC
Please remove the following ebuilds as they are vulnerable to GLSA 200802-08
( http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml ) :

=dev-libs/boost-1.33.1-r1


Note that other (unstable) atoms might be missing from this list that are
vulnerable to the same GLSA. Please remove those as well.
Comment 1 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2009-07-29 15:43:01 UTC
+  29 Jul 2009; Jeremy Olexa <darkside@gentoo.org> boost-1.33.1-r1.ebuild:
+  Remove keywords from boost-1.33.1-r1.ebuild except ~x86-fbsd because it is
+  vulnerable, bug 271712

@bsd: You have no other working boosts that you can keyword???
Comment 2 Alexis Ballier gentoo-dev 2009-08-02 21:04:24 UTC
(In reply to comment #1)
> +  29 Jul 2009; Jeremy Olexa <darkside@gentoo.org> boost-1.33.1-r1.ebuild:
> +  Remove keywords from boost-1.33.1-r1.ebuild except ~x86-fbsd because it is
> +  vulnerable, bug 271712
> 
> @bsd: You have no other working boosts that you can keyword???

no, because of bug #272086 ...
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-08-06 17:27:17 UTC
bsd, do you see the same errors on 1.35.0-r2? The bug report seems specific to 1.37.0-r1.
Comment 4 Alexis Ballier gentoo-dev 2009-08-06 18:05:03 UTC
(In reply to comment #3)
> bsd, do you see the same errors on 1.35.0-r2? The bug report seems specific to
> 1.37.0-r1.

Do we really want to bother with ancient boost? Bug #272086 should be fixed anyway and, I haven't tried for a while but, I recall not being able to compile any boost version besides the one keyworded (if I remember correctly the error was different). I can check again but this sounds more boost maintainers slacking and not fixing their bugs than a real problem thus I fail to see why I should spend hours backporting fixes to 1.35.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2009-08-06 22:04:00 UTC
1.35 is the current stable so I thought I'd ask. If time does not allow it, waiting for boost maintainers sounds like the most future-proof option
Comment 6 Alexis Ballier gentoo-dev 2009-12-10 21:36:54 UTC
as far as bsd is concerned, you can go ahead, i just keyworded latest boost. without much testing though, but it cant be worse.
Comment 7 Dirkjan Ochtman (RETIRED) gentoo-dev 2009-12-11 18:40:31 UTC
Done:

------------------------------------------------------------------------------
Remove dev-libs/boost-1.33.1-r1 and related files (#271712).
(Portage version: 2.1.6.13/cvs/Linux x86_64)
------------------------------------------------------------------------------

/var/cvsroot/gentoo-x86/dev-libs/boost/metadata.xml,v  <--  metadata.xml
new revision: 1.11; previous revision: 1.10
/var/cvsroot/gentoo-x86/dev-libs/boost/ChangeLog,v  <--  ChangeLog
new revision: 1.182; previous revision: 1.181
/var/cvsroot/gentoo-x86/dev-libs/boost/boost-1.33.1-r1.ebuild,v  <--  boost-1.33.1-r1.ebuild
new revision: delete; previous revision: 1.22
/var/cvsroot/gentoo-x86/dev-libs/boost/files/boost-alpha-threads.patch,v  <--  files/boost-alpha-threads.patch
new revision: delete; previous revision: 1.1
/var/cvsroot/gentoo-x86/dev-libs/boost/files/boost-1.33.1-gcc41_visit_each.patch,v  <--  files/boost-1.33.1-gcc41_visit_each.patch
new revision: delete; previous revision: 1.1
/var/cvsroot/gentoo-x86/dev-libs/boost/Manifest,v  <--  Manifest
new revision: 1.239; previous revision: 1.238