<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>109993</bug_id>
          
          <creation_ts>2005-10-20 23:36 0000</creation_ts>
          <short_desc>media-gfx/inkscape security updates available</short_desc>
          <delta_ts>2005-11-28 02:20:30 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.inkscape.org/</bug_file_loc>
          <status_whiteboard>B2 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>neil@darlow.co.uk</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>graphics@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>neil@darlow.co.uk</who>
            <bug_when>2005-10-20 23:36:11 0000</bug_when>
            <thetext>To quote the Inkscape site announcement:

October 9, 2005

Mentalguy has released new point releases of the past two versions of Inkscape
to correct two issues with arbitrary code execution when opening malicious
files. There are no known exploits for this issue, but if you use Inkscape on a
production machine in a manner that invokes files from arbitrary sources, you
may wish to upgrade.


Reproducible: Always
Steps to Reproduce:
1.
2.
3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2005-11-19 14:59:36 0000</bug_when>
            <thetext>Security, any word on this?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-11-20 00:01:48 0000</bug_when>
            <thetext>Graphics please provide an updated ebuild. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>sekretarz@gentoo.org</who>
            <bug_when>2005-11-22 07:19:46 0000</bug_when>
            <thetext>Bumped in portage</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-11-22 09:03:28 0000</bug_when>
            <thetext>Arches please test and mark stable. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-11-22 10:31:54 0000</bug_when>
            <thetext>stable on ppc64 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-11-22 11:20:11 0000</bug_when>
            <thetext>amd64 keywording happy hour: get two keywords for the price of one!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chriswhite@gentoo.org</who>
            <bug_when>2005-11-22 12:19:39 0000</bug_when>
            <thetext>x86 stable.  This program is addictive. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-11-22 12:31:57 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>josejx@gentoo.org</who>
            <bug_when>2005-11-27 11:53:49 0000</bug_when>
            <thetext>Marked ppc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-28 02:20:30 0000</bug_when>
            <thetext>Thx everyone
GLSA 200511-22</thetext>
          </long_desc>
      
    </bug>

</bugzilla>