<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>140498</bug_id>
          
          <creation_ts>2006-07-15 07:44 0000</creation_ts>
          <short_desc>media-gfx/xzgv security removal request</short_desc>
          <delta_ts>2007-10-21 13:12:54 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Ebuilds</component>
          <version>2006.0</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <keywords>PMASKED</keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>102804</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>jakub@gentoo.org</reporter>
          <assigned_to>smithj@gentoo.org</assigned_to>
          <cc>algardas@yahoo.com</cc>
    
    <cc>chriswhite@gentoo.org</cc>
    
    <cc>david.e.pi.3.14@gmail.com</cc>
    
    <cc>gentoo@slave.umbr.cas.cz</cc>
    
    <cc>hkbst@gentoo.org</cc>
    
    <cc>security@gentoo.org</cc>
    
    <cc>smithj@gentoo.org</cc>
    
    <cc>ssuominen@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-07-15 07:44:43 0000</bug_when>
            <thetext>app-admin/gtkdiskfree-1.9.3: vulnerable via glsa(200510-01) ( ver-rev &lt; 1.9.3-r1 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;x86&apos;)

app-doc/chmlib-0.31: vulnerable via glsa(200511-23) ( ver &lt; 0.37.4 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;x86&apos;)
app-doc/chmlib-0.32: vulnerable via glsa(200511-23) ( ver &lt; 0.37.4 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;x86&apos;)
app-doc/chmlib-0.33: vulnerable via glsa(200511-23) ( ver &lt; 0.37.4 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;x86&apos;)
app-doc/chmlib-0.35: vulnerable via glsa(200511-23) ( ver &lt; 0.37.4 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;x86&apos;)

app-misc/lcdproc-0.4.4-r1: vulnerable via glsa(200404-19) ( ver-rev &lt;= 0.4.4-r1 &amp;&amp; ver not =&gt; 0.4.5 ), affects (&apos;amd64&apos;, &apos;x86&apos;)

media-gfx/xzgv-0.8-r1: vulnerable via glsa(200604-10) ( ver-rev &lt; 0.8-r2 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
media-gfx/zgv-5.7-r1: vulnerable via glsa(200604-10) ( ver &lt; 5.9 ), affects (&apos;x86&apos;,)
media-gfx/zgv-5.7-r1: vulnerable via glsa(200411-12) ( ver &lt; 5.8 ), affects (&apos;x86&apos;,)
media-gfx/zgv-5.8: vulnerable via glsa(200604-10) ( ver &lt; 5.9 ), affects (&apos;x86&apos;,)

media-gfx/xli-1.17.0: vulnerable via glsa(200510-26) ( ver-rev &lt; 1.17.0-r2 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;arm&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;ppc&apos;, &apos;ppc-macos&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
media-gfx/xli-1.17.0: vulnerable via glsa(200503-05) ( ver-rev &lt; 1.17.0-r1 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;arm&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;ppc&apos;, &apos;ppc-macos&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
media-gfx/xli-1.17.0-r1: vulnerable via glsa(200510-26) ( ver-rev &lt; 1.17.0-r2 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;arm&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;mips&apos;, &apos;ppc&apos;, &apos;ppc-macos&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
net-www/netscape-flash-6.0.79: vulnerable via glsa(200603-20) ( ver &lt; 7.0.63 ), affects (&apos;x86&apos;,)
net-www/netscape-flash-6.0.79: vulnerable via glsa(200511-21) ( ver &lt; 7.0.61 ), affects (&apos;x86&apos;,)
net-www/netscape-flash-6.0.81: vulnerable via glsa(200603-20) ( ver &lt; 7.0.63 ), affects (&apos;amd64&apos;, &apos;x86&apos;)
net-www/netscape-flash-6.0.81: vulnerable via glsa(200511-21) ( ver &lt; 7.0.61 ), affects (&apos;amd64&apos;, &apos;x86&apos;)
net-www/netscape-flash-7.0.25: vulnerable via glsa(200603-20) ( ver &lt; 7.0.63 ), affects (&apos;amd64&apos;, &apos;x86&apos;)
net-www/netscape-flash-7.0.25: vulnerable via glsa(200511-21) ( ver &lt; 7.0.61 ), affects (&apos;amd64&apos;, &apos;x86&apos;)
net-www/netscape-flash-7.0.61: vulnerable via glsa(200603-20) ( ver &lt; 7.0.63 ), affects (&apos;amd64&apos;, &apos;x86&apos;)

Please, clean up the above. Thanks! ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-07-15 08:07:19 0000</bug_when>
            <thetext>Also:

media-gfx/pngcrush-1.5.10: vulnerable via glsa(200603-18) ( ver &lt; 1.6.2 ), affects (&apos;amd64&apos;, &apos;ppc&apos;, &apos;ppc-macos&apos;, &apos;x86&apos;)

media-libs/libcdaudio-0.99.9: vulnerable via glsa(200504-07) ( ver-rev &lt; 0.99.10-r1 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;mips&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)

net-ftp/gproftpd-8.1.4: vulnerable via glsa(200502-26) ( ver &lt; 8.1.9 ), affects (&apos;sparc&apos;, &apos;x86&apos;)
net-ftp/gproftpd-8.1.6: vulnerable via glsa(200502-26) ( ver &lt; 8.1.9 ), affects (&apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>antarus@gentoo.org</who>
            <bug_when>2006-07-15 10:26:24 0000</bug_when>
            <thetext>Treecleaners doesn&apos;t really do this at present, although we may expand it in the future.  Co-ordinate between qa and security.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-07-15 12:05:23 0000</bug_when>
            <thetext>Also:

net-ftp/ftpd-0.17: vulnerable via glsa(200511-11) ( ver-rev &lt; 0.17-r3 ), affects (&apos;amd64&apos;, &apos;sparc&apos;, &apos;x86&apos;)
net-ftp/ftpd-0.17-r1: vulnerable via glsa(200511-11) ( ver-rev &lt; 0.17-r3 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)
net-ftp/ftpd-0.17-r2: vulnerable via glsa(200511-11) ( ver-rev &lt; 0.17-r3 ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;ppc&apos;, &apos;sparc&apos;, &apos;x86&apos;)

and finally (needs zebedee-2.5.3 stabilized on s390)

net-misc/zebedee-2.5.2: vulnerable via glsa(200509-14) ( ver &lt; 2.5.3 &amp;&amp; not ( ver = 2.4.1 &amp;&amp; ver-rev =&gt; 2.4.1-r1 ) ), affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;mips&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;s390&apos;, &apos;sparc&apos;, &apos;x86&apos;)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chriswhite@gentoo.org</who>
            <bug_when>2006-08-05 18:59:24 0000</bug_when>
            <thetext>media-gfx/xzg &lt;-- smithj was seen about 3 days ago, so I want to wait for him on this one.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chriswhite@gentoo.org</who>
            <bug_when>2006-08-05 19:15:18 0000</bug_when>
            <thetext>net-misc/zebedee waiting on s390
media-gfx/xzg waiting on smithj

everything else is done, cheers.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chriswhite@gentoo.org</who>
            <bug_when>2006-08-05 21:26:08 0000</bug_when>
            <thetext>Smithj said he&apos;s going to mask xzg so I&apos;m going to skip that one and let him mask/remove action on it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>smithj@gentoo.org</who>
            <bug_when>2006-08-07 13:37:04 0000</bug_when>
            <thetext>media-gfx/xzgv masked pending removal; there are much better image viewing utilities out there which are maintained.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hkbst@gentoo.org</who>
            <bug_when>2006-08-08 01:30:09 0000</bug_when>
            <thetext>xzgv is in the fluxbox desktop guide, which is why I have it installed. what would be a good replacement?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>toddmarimon@earthlink.net</who>
            <bug_when>2006-08-08 22:13:20 0000</bug_when>
            <thetext>I too need a replacement.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo@slave.umbr.cas.cz</who>
            <bug_when>2006-08-10 10:41:57 0000</bug_when>
            <thetext>&quot;media-gfx/xzgv masked pending removal; there are much better image viewing
utilities out there which are maintained&quot;

please, could you advise some goog image viewer? I have already tried many viewers, but none have met my expectations but xzgv. I start using zgv on console and I was happy it is for X. It&apos;s simple (two pannels) and it can change image very fast using &quot;space&quot; and &quot;b&quot; keys. Is the any image viewer with this features?

- like ACDSee
- using simple interface
- possible to use only with keys (no mouse)
- only two pannel (directory navigation and file list on one, and the image on the other) - when I used ACDSee, I have switched all useless pannels and let only directory structure and file list
- is really fast
- can do simple image manipulation (zoom, fit to screen-enlarge,shrink), rotate
- can do simple file management (mkdir, rmdir, delete, copy, move)

the other very good image viewer I found is links2 html broswer (but it cannot do file management and more image manipulation)

Is there any other simple image viewer like xzgv which could be fine for me?

Thank you for answer.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-08-10 10:54:39 0000</bug_when>
            <thetext>
&gt; please, could you advise some goog image viewer? I have already tried many
&gt; viewers, but none have met my expectations but xzgv. I start using zgv on
&gt; console and I was happy it is for X. It&apos;s simple (two pannels) and it can
&gt; change image very fast using &quot;space&quot; and &quot;b&quot; keys. Is the any image viewer with
&gt; this features?

i will now use try to use gqview...

but i like xzgv a lot and i would like to keep it... but i&apos;m not allowed (yet?) to maintain gentoo packages... :(
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>antarus@gentoo.org</who>
            <bug_when>2006-08-10 11:07:40 0000</bug_when>
            <thetext>(In reply to comment #11)
&gt; &gt; please, could you advise some goog image viewer? I have already tried many
&gt; &gt; viewers, but none have met my expectations but xzgv. I start using zgv on
&gt; &gt; console and I was happy it is for X. It&apos;s simple (two pannels) and it can
&gt; &gt; change image very fast using &quot;space&quot; and &quot;b&quot; keys. Is the any image viewer with
&gt; &gt; this features?
&gt; 
&gt; i will now use try to use gqview...
&gt; 
&gt; but i like xzgv a lot and i would like to keep it... but i&apos;m not allowed (yet?)
&gt; to maintain gentoo packages... :(
&gt; 

http://bugs.gentoo.org/show_bug.cgi?id=135271

Do your second quiz and get it approved.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-08-11 02:43:26 0000</bug_when>
            <thetext>&gt; 
&gt; Do your second quiz and get it approved.

yes, yes, as soon as i have time to learn all that stuff ! :)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>algardas@yahoo.com</who>
            <bug_when>2006-08-17 09:17:21 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; media-gfx/xzgv masked pending removal; there are much better image viewing
&gt; utilities out there which are maintained.
&gt; 

please, don&apos;t remove xzgv from portage. I have tried all other image viewers I could find in portage and none were as fast (to load, to use) and as fitting to my needs. Of course, if you can list some &quot;better image viewing utilities&quot;, I am eager to hear it.

On the other hand... xzgv seems unmaintained upstream, so the old users will have to keep one ebuild in an overlay or will have to install it manually and new users won&apos;t be presented to security issues it presents...

And anyway, Raphael Marichez, how is your progress becoming a maintainer? :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-08-17 09:27:02 0000</bug_when>
            <thetext>Folks really, moaning here about a tool that&apos;s been dead upstream for 3+ years doesn&apos;t do any good unless you are willing to take it over upstream and maintain the code. Also, bugzilla is not exactly a place to chat about good image viewers.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo@slave.umbr.cas.cz</who>
            <bug_when>2006-09-17 11:09:02 0000</bug_when>
            <thetext>Hi xzgv lovers:)

I&apos;ve found a few days ago new project, new image viewer ACDSee like, called Goby. I&apos;ve tried it and I&apos;ve created ebuild for it. It&apos;s in development, but it this stage it looks great to me. Can anyone manage ebuild for this project? http://goby.sf.net.

Sorry for chating here about image viewers.

Wolf.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo@slave.umbr.cas.cz</who>
            <bug_when>2006-09-17 11:10:16 0000</bug_when>
            <thetext>Created an attachment (id=97268)
Ebuild for Goby

Here is my ebuild for Goby.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-09-17 11:24:38 0000</bug_when>
            <thetext>Uh, stop! This bug is about *cleaning* up vulnerable cruft. Go file a new one for Goby or whatever else. No ebuilds attached here, please. Thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pdenapo@gmail.com</who>
            <bug_when>2006-10-01 16:35:42 0000</bug_when>
            <thetext>Please don&apos;t remove xzgv, it is a nice simple yet  useful application.
I love it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-10-20 02:52:37 0000</bug_when>
            <thetext>Only media-gfx/xzgv left, all the rest done.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>z35_11@yahoo.com</who>
            <bug_when>2006-11-04 20:47:28 0000</bug_when>
            <thetext>Do not remove xzgv !!! i&apos;ll deal w/ xmms, but not xzgv...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2006-11-11 21:38:37 0000</bug_when>
            <thetext>mega bugs suck; file individual ones in the future</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pacho@condmat1.ciencias.uniovi.es</who>
            <bug_when>2006-11-26 11:09:46 0000</bug_when>
            <thetext>What is the current problem of xzgv?

Thanks a lot for information :-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pacho@condmat1.ciencias.uniovi.es</who>
            <bug_when>2006-11-27 04:14:36 0000</bug_when>
            <thetext>Why will xzgv-0.8-r2 be removed?

In main post says:
media-gfx/xzgv-0.8-r1: vulnerable via glsa(200604-10) ( ver-rev &lt; 0.8-r2 ),
affects (&apos;alpha&apos;, &apos;amd64&apos;, &apos;hppa&apos;, &apos;ia64&apos;, &apos;ppc&apos;, &apos;ppc64&apos;, &apos;sparc&apos;, &apos;x86&apos;)

But 0.8-r2 is not affected by this bug http://bugs.gentoo.org/show_bug.cgi?id=127008

Then, 0.8-r2 doesn&apos;t need to be removed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pacho@condmat1.ciencias.uniovi.es</who>
            <bug_when>2006-12-10 04:59:09 0000</bug_when>
            <thetext>xzgv-0.8-r2 is not affected by security bug, please, unmask it</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>slong@rathaus.eclipse.co.uk</who>
            <bug_when>2007-05-18 11:33:57 0000</bug_when>
            <thetext>Um is it possible to unmask this then? (I don&apos;t see the point in filing a new bug.)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-07-07 22:17:32 0000</bug_when>
            <thetext>Still in tree and using GTK+-1.2. Entry in package.mask is getting stale. Please remove.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-07-20 08:03:34 0000</bug_when>
            <thetext>Jonathan, can we get rid of this?

GTK+-1.2 needs to die.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>smithj@gentoo.org</who>
            <bug_when>2007-07-20 13:48:54 0000</bug_when>
            <thetext>kill it. kill it with fire</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-07-21 07:50:25 0000</bug_when>
            <thetext>killed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>slong@rathaus.eclipse.co.uk</who>
            <bug_when>2007-09-02 09:51:42 0000</bug_when>
            <thetext>(In reply to comment #18)
&gt; Uh, stop! This bug is about *cleaning* up vulnerable cruft.

This is *not* _vulnerable_ any more. *plop* ;P



</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>david.e.pi.3.14@gmail.com</who>
            <bug_when>2007-10-21 13:12:54 0000</bug_when>
            <thetext>It seems that xzgv has a new maintainer so I have opened bug 196597, requesting a new ebuild for xzgv-0.9 (which now uses gtk2 and imlib2).

Sorry I didn&apos;t know if it was better to add the ebuild here or if it was better to  fill a new bug report for it... </thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>97268</attachid>
            <date>2006-09-17 11:10 0000</date>
            <desc>Ebuild for Goby</desc>
            <filename>goby-0.3.5.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA2IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6ICQKCkRFU0NSSVBUSU9OPSJHb2J5IGlzIGFuIGltYWdlIHZpZXdlciBiYXNlZCBvbiB0aGUg
R1RLKyB0b29sa2l0LiBUaGUgYWltIGlzIHRvIHByb3ZpZGUgYW4gaW50dWl0aXZlLCBBQ0RTZWUt
bGlrZSB1c2VyIGV4cGVyaWVuY2UuIgpIT01FUEFHRT0iaHR0cDovL2dvYnkuc291cmNlZm9yZ2Uu
bmV0LyIKU1JDX1VSST0ibWlycm9yOi8vc291cmNlZm9yZ2UvJHtQTn0vJHtQfS50YXIuYnoyIgoK
TElDRU5TRT0iR1BMIgpLRVlXT1JEUz0ieDg2IgpJVVNFPSIiClJFU1RSSUNUPSJtaXJyb3IgcHJp
bWFyeXVyaSIKCkRFUEVORD0ieDExLWxpYnMvZ3RrKwoJZGV2LWxpYnMvZ2xpYgoJZ25vbWUtYmFz
ZS9nbm9tZS12ZnMiCgpSREVQRU5EPSJ4MTEtbGlicy9ndGsrCglkZXYtbGlicy9nbGliCglnbm9t
ZS1iYXNlL2dub21lLXZmcyIKCnNyY19pbnN0YWxsKCkgewoJbWFrZSBpbnN0YWxsIERFU1RESVI9
JHtEfQp9Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>