Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 56016 - dev-libs/cyrus-sasl-2.1.18-r2 includes security fixes
Summary: dev-libs/cyrus-sasl-2.1.18-r2 includes security fixes
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A1 [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2004-07-03 20:52 UTC by Tuan Van (RETIRED)
Modified: 2011-10-30 22:40 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tuan Van (RETIRED) gentoo-dev 2004-07-03 20:52:41 UTC
net-mail would like to remove dev-libs/cyrus-sasl-2.1.17 from portage. Please stable .18 on your arch a soon as you can. Thanks.
Comment 1 Cory Visi (RETIRED) gentoo-dev 2004-07-06 21:15:00 UTC
Sorry to do this over guys, but there was a security fix and I brought in the old pam_mysql-friendly authentication method so everyone can upgrade. This is pretty important. Please mark it stable if you can.

This is now: dev-libs/cyrus-sasl-2.1.18-r1

Tuan, can you test this, too?
Comment 2 Tuan Van (RETIRED) gentoo-dev 2004-07-06 21:37:20 UTC
Cory, if this is security related, IMO we need to re-assign this bug to security@g.o with all the info.
Comment 3 Kurt Lieber (RETIRED) gentoo-dev 2004-07-07 02:15:54 UTC
re-assigning to security.  Cory -- many thanks for getting this patched so quickly.
Comment 4 Kurt Lieber (RETIRED) gentoo-dev 2004-07-07 02:25:39 UTC
assigning A0 rating, pending further disclosure of information about the vulnerability
Comment 5 Kurt Lieber (RETIRED) gentoo-dev 2004-07-07 02:27:54 UTC
need x86 and ppc marked stable before we can issue a GLSA.  Current keywords on 2.1.18 are:

cyrus-sasl-2.1.18.ebuild:KEYWORDS="~x86 ~ppc sparc ~mips ~alpha arm hppa amd64 ~ia64 s390 ppc64"
Comment 6 Aron Griffis (RETIRED) gentoo-dev 2004-07-07 09:23:48 UTC
marked stable on alpha and ia64
Comment 7 Tuan Van (RETIRED) gentoo-dev 2004-07-07 10:15:56 UTC
tested on x86. maked stable.
Comment 8 Tuan Van (RETIRED) gentoo-dev 2004-07-07 10:19:56 UTC
CC arches have stable keywords in previous versions.
Comment 9 Tuan Van (RETIRED) gentoo-dev 2004-07-07 11:22:15 UTC
stabled on amd64, remove CC
Comment 10 Thierry Carrez (RETIRED) gentoo-dev 2004-07-07 13:57:27 UTC
Still missing arm hppa mips ppc ppc64 s390 and sparc stable on 2.1.18-r1.
Comment 11 Christian Birchinger (RETIRED) gentoo-dev 2004-07-07 15:33:09 UTC
stable on sparc
Comment 12 Wolfram Schlich (RETIRED) gentoo-dev 2004-07-07 15:48:54 UTC
please see #56389 - there are problems with cyrus-sasl-2.1.18-r1
Comment 13 Wolfram Schlich (RETIRED) gentoo-dev 2004-07-07 16:09:25 UTC
does anybody know why there was this change in /etc/sasl2/smtpd.conf
--8<--
-pwcheck_method: saslauthd
-mech_list: plain login
+pwcheck_method:pam
--8<--
? This way Postfix doesn't use the saslauthd anymore, which I think is bad.
Comment 14 Tuan Van (RETIRED) gentoo-dev 2004-07-07 16:28:16 UTC
@comment #13: that file is owned by postfix. Please file a seperate bug. Thanks.
Comment 15 Cory Visi (RETIRED) gentoo-dev 2004-07-07 19:15:07 UTC
Ok, I got rid of that bug. We're up to -r2. Shouldn't create any other stability problems though.
Comment 16 Wolfram Schlich (RETIRED) gentoo-dev 2004-07-08 00:53:26 UTC
the problem with -r1 that should have been fixed in -r2 still persists.
see bug #56389.
Comment 17 Thierry Carrez (RETIRED) gentoo-dev 2004-07-20 05:33:09 UTC
ppc: GLSA is blocked waiting for your keyword. Please mark dev-libs/cyrus-sasl-2.1.18-r2 stable.
Comment 18 Daniel Ostrow (RETIRED) gentoo-dev 2004-07-20 18:56:30 UTC
Stable on PPC. Very sorry for the delay.
Comment 19 Thierry Carrez (RETIRED) gentoo-dev 2004-07-21 01:11:24 UTC
Ready for a GLSA
arm, hppa, mips, ppc64, s390 : rememebr to mark stable to benefit from the GLSA
Comment 20 SpanKY gentoo-dev 2004-08-02 04:43:08 UTC
added arm/hppa to stable
Comment 21 Pieter Van den Abeele (RETIRED) gentoo-dev 2004-08-12 12:20:09 UTC
removed ppc from glsa
Comment 22 Tom Gall (RETIRED) gentoo-dev 2004-08-14 12:27:04 UTC
removing ppc64 from bug, package marked stable
Comment 23 Joshua Kinard gentoo-dev 2004-09-20 12:34:48 UTC
mips stable.
Comment 24 SpanKY gentoo-dev 2004-09-21 16:38:52 UTC
s390 stable z0r
Comment 25 Thierry Carrez (RETIRED) gentoo-dev 2004-10-07 08:51:09 UTC
GLSA 200410-05, at least