<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>102374</bug_id>
          
          <creation_ts>2005-08-13 07:29 0000</creation_ts>
          <short_desc>www-apps/egroupware XML-RPC Vulnerabilities round 2</short_desc>
          <delta_ts>2005-08-24 12:58:27 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B1 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>web-apps@gentoo.org</cc>
    
    <cc>yoswink@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-13 07:29:32 0000</bug_when>
            <thetext>see bug #102324</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-14 22:06:39 0000</bug_when>
            <thetext>Now instead see bug #102576 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2005-08-16 12:18:44 0000</bug_when>
            <thetext>egroupware-1.0.0.009 in CVS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-16 13:05:25 0000</bug_when>
            <thetext>Arches please test and mark stable. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-08-16 14:45:18 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2005-08-17 03:22:27 0000</bug_when>
            <thetext>stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2005-08-20 10:43:23 0000</bug_when>
            <thetext>egroupware-1.0.0.009 stable on alpha.

A little note for our web-apps maintainers:

During the configuration of egroupware it complains about the lack of the gd
library which is needed to show an especific type of diagrams.

Nothing in the ebuild seems to reflect this so, maybe include a USE flag called
 &quot;diagrams&quot; (or whatever) which enabled a RDEPEND on media-libs/gd could be good
idea. 

I think, something similiar happends with the imap extension.

Thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2005-08-20 16:26:42 0000</bug_when>
            <thetext>Could you post the errors you got?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2005-08-20 19:27:55 0000</bug_when>
            <thetext>Sure:

If I run the checks in: /$egroupware-vdir/setup/check_install.php, it gives me
the following errors:

[*] Checking extension imap is loaded or loadable: False
The imap extension is needed by the two email apps (even if you use email with
pop3 as protocoll).

[*] Checking for GD support...: False
Your PHP installation does not have appropriate GD support. You need gd library
version 1.8 or newer to see Gantt charts in projects.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2005-08-21 10:31:50 0000</bug_when>
            <thetext>Thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-08-24 06:58:36 0000</bug_when>
            <thetext>amd64: you&apos;re late to mark stable, GLSA waits.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hparker@gentoo.org</who>
            <bug_when>2005-08-24 08:41:12 0000</bug_when>
            <thetext>Stable on amd64, sorry for the delay</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-08-24 12:06:22 0000</bug_when>
            <thetext>CVS says current keywords are :
KEYWORDS=&quot;alpha ~amd64 ~hppa ppc ~sparc x86&quot;

hparker: apparently the keyword didn&apos;t make it to CVS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-08-24 12:23:37 0000</bug_when>
            <thetext>OK it&apos;s fixed now, ready for GLSa</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-08-24 12:58:27 0000</bug_when>
            <thetext>GLSA 200508-14</thetext>
          </long_desc>
      
    </bug>

</bugzilla>