<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>136415</bug_id>
          
          <creation_ts>2006-06-11 07:59 0000</creation_ts>
          <short_desc>app-text/acroread: &lt;7.0.8 unspecified vulnerability ?</short_desc>
          <delta_ts>2006-08-02 23:46:24 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>INVALID</resolution>
          <bug_file_loc>http://www.adobe.com/support/techdocs/327817.html</bug_file_loc>
          <status_whiteboard>B? [] Falco</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>falco@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>nelchael@gentoo.org</cc>
    
    <cc>printing@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-06-11 07:59:54 0000</bug_when>
            <thetext>http://www.adobe.com/support/techdocs/327817.html says :

&quot;Security: several security bug fixes have been made, including one considered critical.&quot;

for the 7.0.8 update

how should we consider this ?
In doubt, printing team, could you introduce acroread-7.0.8 into portage of possible ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>genstef@gentoo.org</who>
            <bug_when>2006-06-17 19:43:58 0000</bug_when>
            <thetext>I added a masked 7.0.8 ebuild because it does not have all localization yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-06-18 04:31:11 0000</bug_when>
            <thetext>(In reply to comment #1)
&gt; I added a masked 7.0.8 ebuild because it does not have all localization yet.
&gt; 

I suppose we can&apos;t stabilize this version.

Back to [upstream] status in order to wait for a valid upstream version.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-07-24 09:01:44 0000</bug_when>
            <thetext>ok, we waited long enough. i dont care a lot about localization, imho is security more important. what do you think?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-07-24 21:29:16 0000</bug_when>
            <thetext>Yes, let&apos;s shove it out, preferrably with an enotice describing security overrules understandability .-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-07-29 05:41:34 0000</bug_when>
            <thetext>I agree.
genstef/printing : please unmask it or advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>genstef@gentoo.org</who>
            <bug_when>2006-07-29 07:49:36 0000</bug_when>
            <thetext>adobe has released some language tarballs and I have unmasked the new version -  go ahead :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-07-29 08:43:59 0000</bug_when>
            <thetext>amd64 and x86, please test and stable 7.0.8, thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tsunam@gentoo.org</who>
            <bug_when>2006-07-30 20:19:25 0000</bug_when>
            <thetext>*thumbs up* It works like it should ^.^;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2006-07-31 04:38:45 0000</bug_when>
            <thetext>amd64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-07-31 13:42:35 0000</bug_when>
            <thetext>Voting yes, one unknown critical.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-07-31 14:00:53 0000</bug_when>
            <thetext>voting yes too (one critical, acroread is widely used)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-07-31 22:06:10 0000</bug_when>
            <thetext>yes</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-08-01 00:46:39 0000</bug_when>
            <thetext>okokOK:-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-08-02 09:06:41 0000</bug_when>
            <thetext>According to RH CVE-2006-3093 does not affect the Linux version, so I suggest we close this one as INVALID.

Comments?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-08-02 09:34:43 0000</bug_when>
            <thetext>Hm, SuSE still released new packages. Do they know something the others don&apos;t?

http://lists.suse.com/archive/suse-security-announce/2006-Jul/0004.html
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-08-02 09:52:14 0000</bug_when>
            <thetext>No, they didn&apos;t know what others know now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-08-02 10:54:51 0000</bug_when>
            <thetext>Great, I downloaded that bloat and guess what, there&apos;s no changelog/release note inside. Probably to save bandwidth. Ha, ha. Just gotta love them.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-08-02 23:46:24 0000</bug_when>
            <thetext>Closing as INVALID.

Feel free to reopen if you disagree.

Sorry for the noise.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>