<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>105695</bug_id>
          
          <creation_ts>2005-09-12 08:31 0000</creation_ts>
          <short_desc>x11-libs/qt includes vulnerable zlib</short_desc>
          <delta_ts>2006-03-23 19:45:26 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.trolltech.com/developer/changes/changes-3.3.5.html</bug_file_loc>
          <status_whiteboard>B2? [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>105719</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kde@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-09-12 08:31:11 0000</bug_when>
            <thetext>It appears as if qt is using it&apos;s own version of zlib if the zlib USE flag is  
not set.  
  
From 3.3.5 Changelog: 
 
Added security patches for zlib: CAN-2005-1849, CAN-2005-2096</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-12 09:01:52 0000</bug_when>
            <thetext>Hm. Let&apos;s say USE=-zlib is quite uncommon and rate this B2.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-17 05:39:26 0000</bug_when>
            <thetext>KDE team: your position on this, please.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2005-09-18 07:21:25 0000</bug_when>
            <thetext>FYI: 3.3.5 is in portage now, as unstable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-18 09:35:32 0000</bug_when>
            <thetext>Thanks Caleb. Is it a candidate for stable right now ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>greg_g@gentoo.org</who>
            <bug_when>2005-09-19 03:03:42 0000</bug_when>
            <thetext>(In reply to comment #4) 
&gt; Thanks Caleb. Is it a candidate for stable right now ? 
 
I think not, see bug 106402. 
 
I suggest to commit qt-3.3.4-r8, the only difference to -r7 being that it 
forces &quot;-system-zlib&quot; as a compilation option. 
qt-3.3.4-r7 was ready to go stable, so qt-3.3.4-r8 could go stable right now. 
 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-09-19 03:40:39 0000</bug_when>
            <thetext>Back to ebuild status, waiting for a suitable ebuild to mark stable.  </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2005-09-19 05:15:37 0000</bug_when>
            <thetext>#5 works for me. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-09-19 05:58:57 0000</bug_when>
            <thetext>Yeah it does for me as well if -r8 gets committed. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2005-09-19 07:06:46 0000</bug_when>
            <thetext>-r8 is committed, but not yet stable on any arches.  I don&apos;t see why it can&apos;t 
go stable right away, but I&apos;d like one more opinion on the matter (greg?). </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>greg_g@gentoo.org</who>
            <bug_when>2005-09-19 08:32:00 0000</bug_when>
            <thetext>I agree that it can go stable right now. Actually I was going to propose -r7 
for stable just before this bug showed up. 
 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-19 08:59:03 0000</bug_when>
            <thetext>OK, let&apos;s go then: archs please test and mark 3.3.4-r8 stable
Target KEYWORDS=&quot;alpha amd64 hppa ia64 mips ppc ppc64 ~ppc-macos sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cryos@gentoo.org</who>
            <bug_when>2005-09-19 10:39:28 0000</bug_when>
            <thetext>This version also introduces a dep on ~dev-db/qt-unixODBC-3.3.4 which isn&apos;t 
currently stable on amd64 and has an open security bug against it (bug 105719) 
- advise on this please. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2005-09-19 19:04:33 0000</bug_when>
            <thetext>I&apos;ve committed a patch to the qt-unixodbc ebuild that should fix the RUNPATH problem.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-09-19 21:15:09 0000</bug_when>
            <thetext>stable on ppc64 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-09-20 07:25:06 0000</bug_when>
            <thetext>sparc stable (with qt-unixODBC-3.3.4-r1).
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-09-20 10:27:13 0000</bug_when>
            <thetext>Stable on hppa, ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cryos@gentoo.org</who>
            <bug_when>2005-09-20 11:42:42 0000</bug_when>
            <thetext>Looks good - stable on amd64. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-09-21 02:34:48 0000</bug_when>
            <thetext>Looks ok on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2005-09-21 18:43:01 0000</bug_when>
            <thetext>Stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-22 01:59:19 0000</bug_when>
            <thetext>Common GLSA with the qt-unixodbc thing ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-09-22 04:02:54 0000</bug_when>
            <thetext>Let&apos;s do a common GLSA with qt. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-09-22 04:06:29 0000</bug_when>
            <thetext>with qt-unixodbc of course :-) </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-09-26 13:56:00 0000</bug_when>
            <thetext>GLSA 200509-18  
  
ia64 and mips don&apos;t forget to mark stable to benifit from the GLSA. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2005-09-28 18:37:05 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>