<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>153704</bug_id>
          
          <creation_ts>2006-11-01 08:49 0000</creation_ts>
          <short_desc>app-emulation/emul-linux-x86-qtlibs(?): khtml/qt integer overflow (CVE-2006-4811)</short_desc>
          <delta_ts>2007-03-07 15:41:31 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>165270</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>vorlon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>amd64@gentoo.org</cc>
    
    <cc>blubb@gentoo.org</cc>
    
    <cc>dystopianray@gmail.com</cc>

      

      
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-11-01 08:49:54 0000</bug_when>
            <thetext>pls see bug 151838 for details and check/fix the package if needed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-11-03 04:23:59 0000</bug_when>
            <thetext>ok... i have tried to get a comment from amd64 on the other bug before, pinged people in #-dev a long while ago...

well... CC&apos;ing amd64, pls validate</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2006-11-03 08:34:36 0000</bug_when>
            <thetext>baselibs, qtlibs and gtklibs need new versions. I&apos;ll try to see if I can do it next weekend if herbs doesn&apos;t get to it first.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2006-11-04 05:37:22 0000</bug_when>
            <thetext>I personally have no clue on how the package is built these days, sorry :-/
Should remove myself from metadata.xml i suppose :-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-20 22:59:44 0000</bug_when>
            <thetext>tester, any news on this one?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-12-03 11:42:06 0000</bug_when>
            <thetext>hmpf... it has been over a month now
has there been any progress here?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-10 22:00:38 0000</bug_when>
            <thetext>reping</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-11 18:18:38 0000</bug_when>
            <thetext>PONG!

I&apos;ve got emul-linux-x86-qtlibs-10.0 ready. The SRC_URI files are uploading right now, so I can commit the the ebuild in ~4h.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-11 18:28:06 0000</bug_when>
            <thetext>Uhm, actually, not quite yet, as this also needs a new baselibs which is quite some work, but &quot;we&apos;re working on it&quot;.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-11 22:35:04 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; Uhm, actually, not quite yet, as this also needs a new baselibs which is quite
&gt; some work, but &quot;we&apos;re working on it&quot;.
&gt; 

OK :)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-12 09:13:58 0000</bug_when>
            <thetext>10.0 is in the tree, marked ~amd64. Since it required a complete rebuild of ~40 packages, I&apos;d like to wait a bit before stablizing it, I&apos;m almost sure something broke. It&apos;s not like a few more days would hurt after 3 1/2 months anyway...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-16 10:30:54 0000</bug_when>
            <thetext>Alright, it worked out a lot better then I expected it to, so emul-linux-x86-qtlibs-10.0 which fixes the issue is marked stable on amd64 now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dystopianray@gmail.com</who>
            <bug_when>2007-02-16 15:13:40 0000</bug_when>
            <thetext>Updating these ebuilds seems to have broken the other emul-linux-x86-* ebuilds that are still putting things in /emul.

I had to update emul-linux-x86-sdl and emul-linux-x86-gtklibs to the ~arch versions that put everything in /lib32 and /usr/lib32 or their libraries weren&apos;t being detected and revdep-rebuild was spitting out missing library errors.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-16 15:51:42 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; Updating these ebuilds seems to have broken the other emul-linux-x86-* ebuilds
&gt; that are still putting things in /emul.

Thanks for catching that, I had this mix installed thus it worked fine. I just marked all the latest emul-packages stable so everything goes to (/usr)/lib32.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-17 23:36:58 0000</bug_when>
            <thetext>Thanks to all the developers and testers :)


it&apos;s A2 or B2 so it merits a GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-03-07 15:41:31 0000</bug_when>
            <thetext>this was GLSA 200703-06

so let&apos;s close it :)

</thetext>
          </long_desc>
      
    </bug>

</bugzilla>