Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 295884 - Rekeyword =app-office/koffice-meta-2.1.0
Summary: Rekeyword =app-office/koffice-meta-2.1.0
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo KDE team
URL:
Whiteboard: Pending: 2010-01-01
Keywords: KEYWORDREQ
Depends on: 296104
Blocks: 295327
  Show dependency tree
 
Reported: 2009-12-05 17:58 UTC by Samuli Suominen (RETIRED)
Modified: 2010-01-24 13:44 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Samuli Suominen (RETIRED) gentoo-dev 2009-12-05 17:58:32 UTC
This is really a security bug as kde-base/kdelibs:3.5 is affected by at least these,

Remote code execution (CVE-2009-1690), bug 274566
Remote code execution (CVE-2009-1725), bug 279027
SSL certificate spoofing (CVE-2009-2702), bug 285018

And this is blocking it's masking.

Bug 295327 is soon to follow.
Comment 1 Samuli Suominen (RETIRED) gentoo-dev 2009-12-05 17:59:50 UTC
You should get the package list from the meta ebuild itself.
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2009-12-06 06:07:13 UTC
Um, so why isn't security@g.o the assignee?? Because kde@.g.o put an unrequested and undesired mask on kde-3.5?
Comment 3 Tobias Klausmann (RETIRED) gentoo-dev 2009-12-06 15:01:23 UTC
Note that this will take a while on alpha since the packages aren't exactly lightweight. But we're aware of this bug and its urgency.
Comment 4 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-12-06 15:31:48 UTC
(In reply to comment #2)
> Um, so why isn't security@g.o the assignee?? Because kde@.g.o put an
> unrequested and undesired mask on kde-3.5?

Jeroen,

Gentoo is probably one of the last distros still having KDE-3.5 around. The reason we waited this long was the feeling that KDE-4 wasn't yet as stable as KDE-3.5.
Unfortunately, upstream simply stopped caring about KDE-3.5 a long time ago and as a result we now have a few serious security holes in KDE-3.5. The Gentoo KDE team could no longer trust on KDE-3.5 and that's what lead to all the rush with the KDE-4 stabilization and getting 3.5 masked. The security team does have open bugs for some of the security issues affecting KDE-3.5.
Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2009-12-24 12:56:02 UTC
Masking KOffice 1.x will proceed 2010-01-01 as it doesn't compile anymore on ~arch due to new Autoconf >= 2.64.
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2010-01-14 02:08:40 UTC
Stable for HPPA.
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2010-01-16 14:31:51 UTC
alpha/ia64/sparc will pass unless an user requests it(since the keyword was dropped already)
Comment 8 Brent Baude (RETIRED) gentoo-dev 2010-01-20 21:53:14 UTC
~ppc64 done
Comment 9 Brent Baude (RETIRED) gentoo-dev 2010-01-24 13:44:37 UTC
~ppc done; closing as last arch