Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 488986 - =dev-vcs/gitolite-3.5.3.1 version bump
Summary: =dev-vcs/gitolite-3.5.3.1 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal enhancement (vote)
Assignee: Christian Ruppert (idl0r)
URL:
Whiteboard:
Keywords:
: 489856 (view as bug list)
Depends on:
Blocks:
 
Reported: 2013-10-22 10:29 UTC by Manuel Rüger (RETIRED)
Modified: 2013-11-06 02:03 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Manuel Rüger (RETIRED) gentoo-dev 2013-10-22 10:29:13 UTC
2013-10-14 v3.5.3 catch undefined groupnames (when possible)

                    mirroring: async push to slaves

                    (some portability fixes)

                    (a couple of contrib scripts - querying IPA based LDAP
                    servers for group membership, and user key management)

                    allow groups in subconf files (this *may* slow down
                    compilation in extreme cases)

                    make adding repo-specific hooks easier (see cust.mkd or
                    cust.html online for docs)

                    smart http now supports git 1.8.2 and above (which changed
                    the protocol requirements a wee bit)


Please add it to the tree
Comment 1 Markos Chandras (RETIRED) gentoo-dev 2013-10-22 10:35:56 UTC
Maybe not?

http://www.openwall.com/lists/oss-security/2013/10/21/1
Comment 2 Manuel Rüger (RETIRED) gentoo-dev 2013-10-22 10:37:40 UTC
(In reply to Markos Chandras from comment #1)
> Maybe not?
> 
> http://www.openwall.com/lists/oss-security/2013/10/21/1
Thanks, it should be fixed in 3.5.3.1, reassigning to security@g.o

https://github.com/sitaramc/gitolite/commit/3dad4f8e3214d6ab5f71823019a624fa48b055a3
Comment 3 Agostino Sarubbo gentoo-dev 2013-10-22 10:40:48 UTC
This is not a security bug. The bug happened in 3.5.3 which is not in the tree.
Comment 4 Manuel Rüger (RETIRED) gentoo-dev 2013-10-30 06:34:05 UTC
*** Bug 489856 has been marked as a duplicate of this bug. ***
Comment 5 Tim Harder gentoo-dev 2013-11-06 02:03:29 UTC
Added to the tree.