<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>174043</bug_id>
          
          <creation_ts>2007-04-10 16:13 0000</creation_ts>
          <short_desc>www-servers/lighttpd: CRLF parsing and 0-mtime DoS (CVE-2007-18{69|70})</short_desc>
          <delta_ts>2007-06-24 23:55:42 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.lighttpd.net/2007/4/13/lighttpd-1-4-14-released</bug_file_loc>
          <status_whiteboard>B3 [glsa] Falco</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>falco@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bernd@linx.net</cc>
    
    <cc>chainsaw@gentoo.org</cc>
    
    <cc>lars@chaotika.org</cc>
    
    <cc>mips@gentoo.org</cc>
    
    <cc>robbat2@gentoo.org</cc>
    
    <cc>www-servers@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-04-10 16:13:45 0000</bug_when>
            <thetext>CVE-2007-1869 - \r\n\r\n parsing DoS
CVE-2007-1870 - 0 mtime null pointer dereference

Pre-release: http://www.lighttpd.net/assets/2007/4/4/lighttpd-1.4.x.r1719.tar.gz
Release: within a few days, now still confidential.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-13 16:26:04 0000</bug_when>
            <thetext>This one is public now.

www-servers please bump.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-04-13 17:55:22 0000</bug_when>
            <thetext>robbat2: you seem to have touched lighttpd alot lately. care to give your input?

the following patch seems to make it work for me:

--- lighttpd-1.4.13-r3.ebuild   2007-04-10 12:34:20.000000000 +0200
+++ lighttpd-1.4.14.ebuild      2007-04-13 19:46:52.000000000 +0200
@@ -8,7 +8,7 @@

 DESCRIPTION=&quot;Lightweight high-performance web server&quot;
 HOMEPAGE=&quot;http://www.lighttpd.net/&quot;
-SRC_URI=&quot;http://www.lighttpd.net/download/${P}.tar.gz&quot;
+SRC_URI=&quot;http://www.lighttpd.net/assets/2007/4/13/${P}.tar.bz2&quot;

 LICENSE=&quot;BSD&quot;
 SLOT=&quot;0&quot;
@@ -101,7 +101,7 @@
        unpack ${A}
        cd ${S}

-       EPATCH_SUFFIX=&quot;diff&quot; EPATCH_OPTS=&quot;-p1 -l -d ${S}&quot; epatch ${FILESDIR}/${PV} || die &quot;Patching failed!&quot;


        eautoreconf || die

thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-04-14 20:35:21 0000</bug_when>
            <thetext>lighttpd-1.4.15 is in the tree
(almost) all archs are asked to mark it stable. thanks!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-04-14 20:37:35 0000</bug_when>
            <thetext>thanks Thilo.

Indeed, arches, please could you test lighttpd-1.4.15 and mark it stable if the tests are fine. thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-04-14 22:18:51 0000</bug_when>
            <thetext>Stable for HPPA.

Would someone keywording sparc-fbsd kindly fix all this stuff below, thanks. I haven&apos;t done a complete cvs up but I checked a couple of the missing dependencies and nothing seems to have happened in favour of sparc-fbsd since the last version of lighttpd needed keywording.

  DEPEND.badindev                12
   www-servers/lighttpd/lighttpd-1.4.13-r1.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-libs/fcgi&apos;, &apos;dev-lang/php&apos;, &apos;sys-fs/e2fsprogs&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;, &apos;virtual/perl-Test-Harness&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r1.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r3.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-libs/fcgi&apos;, &apos;dev-lang/php&apos;, &apos;sys-fs/e2fsprogs&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;, &apos;virtual/perl-Test-Harness&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r3.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.11.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-libs/fcgi&apos;, &apos;dev-lang/php&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;virtual/perl-Test-Harness&apos;]
   www-servers/lighttpd/lighttpd-1.4.11.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.13.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-libs/fcgi&apos;, &apos;dev-lang/php&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;virtual/perl-Test-Harness&apos;]
   www-servers/lighttpd/lighttpd-1.4.13.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.15.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-libs/fcgi&apos;, &apos;dev-lang/php&apos;, &apos;sys-fs/e2fsprogs&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;, &apos;virtual/perl-Test-Harness&apos;]
   www-servers/lighttpd/lighttpd-1.4.15.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r2.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-libs/fcgi&apos;, &apos;dev-lang/php&apos;, &apos;sys-fs/e2fsprogs&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;, &apos;virtual/perl-Test-Harness&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r2.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
  RDEPEND.badindev               12
   www-servers/lighttpd/lighttpd-1.4.13-r1.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;sys-fs/e2fsprogs&apos;, &apos;dev-lang/php&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r1.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r3.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;sys-fs/e2fsprogs&apos;, &apos;dev-lang/php&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r3.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.11.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-lang/php&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;]
   www-servers/lighttpd/lighttpd-1.4.11.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.13.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;dev-lang/php&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;]
   www-servers/lighttpd/lighttpd-1.4.13.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.15.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;sys-fs/e2fsprogs&apos;, &apos;dev-lang/php&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;]
   www-servers/lighttpd/lighttpd-1.4.15.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r2.ebuild: ~sparc-fbsd(default-bsd/fbsd/6.2/sparc) [&apos;sys-fs/e2fsprogs&apos;, &apos;dev-lang/php&apos;, &apos;net-analyzer/rrdtool&apos;, &apos;&gt;=net-nds/openldap-2.1.26&apos;]
   www-servers/lighttpd/lighttpd-1.4.13-r2.ebuild: ~x86-fbsd(default-bsd/fbsd/6.2/x86) [&apos;dev-libs/libmemcache&apos;, &apos;net-analyzer/rrdtool&apos;]</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>robbat2@gentoo.org</who>
            <bug_when>2007-04-14 22:26:36 0000</bug_when>
            <thetext>There&apos;s another blip with lighttpd that I&apos;m aware of, relating to the startup and not dropping the terminal properly (it was only exposed due to other cleanups in .13-r3).

Either we rebase 1.4.15 to 1.4.13-r2 that has a workaround for it, or we hold off a bit.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-04-14 23:06:44 0000</bug_when>
            <thetext>robbat2: you&apos;re the boss! i took the latest thing in there, expecting it to be
the latest and greatest...

AFAICT the difference between .13-r2 and .14-r3 is the init.d file, which
removes the --background from start-stop-daemon....
so perhaps we should just put that back in (which would be the rebase you were
talking about)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-15 04:47:45 0000</bug_when>
            <thetext>Back to ebuild status to get the init script fixed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-04-15 11:16:34 0000</bug_when>
            <thetext>well, i can&apos;t reproduce the backgrounding isssue to begin with.
anyway - 1.4.15 now installs the .13-r2 init.d.

robbat2: can you please confirm that the &apos;blip&apos; is resolved?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>robbat2@gentoo.org</who>
            <bug_when>2007-04-15 11:33:45 0000</bug_when>
            <thetext>yup, your .15 based on -r2 works fine (no blip).
thanks for getting to it before I did.
I only picked up lighttpd because beu was AWOL.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-04-15 12:08:04 0000</bug_when>
            <thetext>thanks robbat2! i only picked up lighttpd because of the security thing... (as i did about a year ago)...

are we back to stable marking then? it got my go!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>robbat2@gentoo.org</who>
            <bug_when>2007-04-15 12:17:24 0000</bug_when>
            <thetext>yup, good to add arches again.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-15 14:49:45 0000</bug_when>
            <thetext>Sorry for the lag, enjoying a nice spring day here:)

Arches please test and mark stable. Target keywords are:
lighttpd-1.4.15.ebuild:KEYWORDS=&quot;alpha amd64 arm hppa ia64 mips ppc ppc64 sh sparc ~sparc-fbsd x86 ~x86-fbsd&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-04-15 15:02:36 0000</bug_when>
            <thetext>Still stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2007-04-15 15:52:48 0000</bug_when>
            <thetext>the same tests as usual fail:
./mod-rewrite.........# status failed: expected &apos;200&apos;, got &apos;404&apos;
./mod-fastcgi.........# status failed: expected &apos;200&apos;, got &apos;404&apos;

but still works on amd64

Portage 2.1.2.2 (default-linux/amd64/2006.1/desktop, gcc-4.1.1, glibc-2.5-r0, 2.6.20-beyond2 x86_64)
=================================================================
System uname: 2.6.20-beyond2 x86_64 AMD Athlon(tm) 64 X2 Dual Core Processor 4600+
Gentoo Base System release 1.12.9
Timestamp of tree: Sun, 15 Apr 2007 14:20:01 +0000
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31-r5
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.15-r1
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS=&quot;amd64&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;
CFLAGS=&quot;-march=k8 -Os -pipe -msse3 -w&quot;
CHOST=&quot;x86_64-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/php/apache1-php5/ext-active/ /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/splash /etc/terminfo&quot;
CXXFLAGS=&quot;-march=k8 -Os -pipe -msse3 -w&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
EMERGE_DEFAULT_OPTS=&quot;--quiet&quot;
FEATURES=&quot;buildsyspkg ccache collision-protect distlocks metadata-transfer multilib-strict nodoc noinfo parallel-fetch sandbox sfperms strict test userfetch userpriv usersandbox&quot;
GENTOO_MIRRORS=&quot;ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp://ftp.uni-erlangen.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/ ftp://ftp.gentoo.mesh-solutions.com/gentoo/ ftp://pandemonium.tiscali.de/pub/gentoo/ &quot;
LANG=&quot;en_US.UTF-8&quot;
LC_ALL=&quot;en_US.UTF-8&quot;
MAKEOPTS=&quot;-j3 -l3&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_EXTRA_OPTS=&quot;--exclude-from=/etc/portage/rsync_excludes&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --filter=H_**/files/digest-*&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage/overlay&quot;
SYNC=&quot;rsync://rsync.europe.gentoo.org/gentoo-portage&quot;
USE=&quot;X a52 aac acpi alsa amd64 amr audiofile bitmap-fonts bzip2 cairo cdinstall cdr cli cracklib crypt cups dbus dri dts dvd dvdr dvdread emboss encode exif fam firefox fortran gdbm gif gstreamer gtk gtk2 hal iconv jpeg libg++ lirc logrotate mad midi mikmod minimal mp3 mpeg ncurses nptl nptlonly offensive ogg opengl pam pcre php png ppds pppd quicktime readline reflection sdl session smp spl ssl svg symlink tcpd test tiff truetype truetype-fonts type1-fonts unicode v4l vim vorbis x264 xinerama xorg xv xvid zlib&quot; ALSA_CARDS=&quot;emu10k1&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;evdev keyboard&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text&quot; LIRC_DEVICES=&quot;inputlirc&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;nvidia&quot;
Unset:  CTARGET, INSTALL_MASK, LDFLAGS, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>monkeh@monkeh.net</who>
            <bug_when>2007-04-15 17:14:33 0000</bug_when>
            <thetext>Same test failures as Christoph on x86, but otherwise works perfectly.

Portage 2.1.2.2 (default-linux/x86/2006.1, gcc-4.1.1, glibc-2.5-r0, 2.6.20-gentoo-r4 i686)
=================================================================
System uname: 2.6.20-gentoo-r4 i686 AMD Athlon(tm) MP 2400+
Gentoo Base System release 1.12.9
Timestamp of tree: Sun, 15 Apr 2007 15:50:01 +0000
distcc 2.18.3 i686-pc-linux-gnu (protocols 1 and 2) (default port 3632) [disabled]
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31-r5
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.15-r1
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS=&quot;x86&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;i686-pc-linux-gnu&quot;
CFLAGS=&quot;-O2 -march=athlon-mp -pipe&quot;
CHOST=&quot;i686-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/php/apache1-php5/ext-active/ /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/terminfo /etc/texmf/web2c&quot;
CXXFLAGS=&quot;-O2 -march=athlon-mp -pipe&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;ccache distlocks metadata-transfer parallel-fetch sandbox sfperms strict&quot;
GENTOO_MIRRORS=&quot;http://gentoo.blueyonder.co.uk&quot;
LANG=&quot;en_GB.UTF-8&quot;
LINGUAS=&quot;en en_GB&quot;
MAKEOPTS=&quot;-j9&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --filter=H_**/files/digest-*&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage /usr/portage/local/layman/sunrise&quot;
SYNC=&quot;rsync://rsync.europe.gentoo.org/gentoo-portage&quot;
USE=&quot;3dnow 3dnowext X Xaw3d a52 aac aalib acpi alsa amr amrr animgif ao aoss apache2 audacious avi bash-completion berkdb bitmap-fonts bittorrent browserplugin bzip2 cairo ccache cdparanoia cdr cdrom cgi chardet chm clamav clamd cli cpudetection crypt cups curl curlwrappers cursors customlog dbus dga divx dlloader dpms dri dts dvd dvdnav dvdr dvdread dvi eds elf encode esd ethereal exif expat extensions fam fame fastcgi fbcon ffmpeg filepicker finger firefox flac flash flatfile font-server fontconfig foomaticdb fortran freetts gaim gajim gd gdbm gdm geoip gif gimp gimpprint glitz glut gmail gmailtimestamps gmedia gnome gnome-print gnutls gstreamer010 gtk gtk2 gtkhtml gtkspell guile gvim hal hddtemp html httpd icons iconv id3 imagemagick imlib imlib2 injection jabber jpeg lame lcms libcaca libclamav libg++ libnotify libsamplerate libwww lighttpd lm_sensors logitech-mouse logrotate lzo lzw mad madwifi midi mikmod mjpeg mmap mmx mmxext mng modplug mono motif mozbranding moznocompose moznoirc moznomail mozsvg mp3 mp4 mpeg mplayer msn musepack nautilus ncurses network new-login nfs nls no-old-linux no-seamonkey no-suexec nogecko-sdk nogg noplugin nptl nptlonly nsplugin nvidia offensive ogg oggvorbis openal opendoc opengl openssl opensslcrypt oss pam pam_chroot panel-plugin pango pcre pdf pdflib perl php png pop ppds pppd pulseaudio python quicktime rar rdesktop readline real realmedia reflection rtc ruby samba sdl sensord session sftp sftplogging smp smtp sndfile sound sox speex spell spl sqlite sqlite3 sse sse-filters ssl startup-notification subtitles subversion svg svgz swat sysfs syslog tabs taglib tagwriting tcl tcltk tcpd test tga theora threads thunar-vfs thunderbird tidy tiff timidity tk toolbar tools tos transcode truetype truetype-fonts type1-fonts udev uk_bleb uk_rt underscores unicode unzip usb vim vim-pager vim-with-x virus-scan vorbis wavpack win32codecs wma wmp wordperfect wv wxgtk1 wxwindows x264 x86 xanim xcb xchat xchattext xcomposite xext xforms xinerama xinetd xml xmlreader xmlwriter xorg xosd xprint xrandr xscreensaver xsettings xv xvid xvmc zeroconf zip zlib&quot; ALSA_CARDS=&quot;emu10k1&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;keyboard mouse&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;g15&quot; LINGUAS=&quot;en en_GB&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;nv nvidia&quot;
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, LDFLAGS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Portage 2.1.2.2 (default-linux/x86/2006.1, gcc-4.1.1, glibc-2.5-r0, 2.6.21-rc5 i686)
=================================================================
System uname: 2.6.21-rc5 i686 Pentium III (Coppermine)
Gentoo Base System release 1.12.9
Timestamp of tree: Sun, 15 Apr 2007 15:50:01 +0000
distcc 2.18.3 i686-pc-linux-gnu (protocols 1 and 2) (default port 3632) [enabled]
ccache version 2.4 [enabled]
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.15-r1
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS=&quot;x86&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;i686-pc-linux-gnu&quot;
CFLAGS=&quot;-O2 -march=pentium3 -pipe&quot;
CHOST=&quot;i686-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/gconf /etc/php/apache1-php5/ext-active/ /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/terminfo /etc/texmf/web2c&quot;
CXXFLAGS=&quot;-O2 -march=pentium3 -pipe&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;ccache distcc distlocks metadata-transfer parallel-fetch sandbox sfperms strict&quot;
GENTOO_MIRRORS=&quot;http://gentoo.virginmedia.com&quot;
LINGUAS=&quot;en en_GB&quot;
MAKEOPTS=&quot;-j12&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --filter=H_**/files/digest-*&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/portage/local/layman/sunrise&quot;
SYNC=&quot;rsync://atlantis/gentoo-portage&quot;
USE=&quot;X aac bash-completion berkdb bitmap-fonts bzip2 cgi cli cpudetection cracklib crypt curl dbus doc dri fastcgi fftw flac fontconfig fortran gdbm glitz gnutls gpm gtk hal hddtemp iconv isdnlog jack jack-tmpfs jpeg libg++ libnotify lm_sensors mad midi mmx modplug mp3 mpi musepack ncurses netjack nls nptl nptlonly numeric offensive ogg pam pango pcre perl php plugins png ppds pppd pulseaudio python readline reflection samba sensord server session sndfile spl sse ssl svg tcpd timidity truetype truetype-fonts type1-fonts unicode vorbis wavpack wma x86 xml xorg xpm zlib&quot; ALSA_CARDS=&quot;ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;keyboard mouse evdev&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text&quot; LINGUAS=&quot;en en_GB&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;mach64 vga vesa&quot;
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LDFLAGS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-04-15 19:08:41 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2007-04-15 19:14:08 0000</bug_when>
            <thetext>x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2007-04-15 20:17:08 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-04-16 09:59:38 0000</bug_when>
            <thetext>ia64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-04-16 13:19:23 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lars@chaotika.org</who>
            <bug_when>2007-04-17 08:46:38 0000</bug_when>
            <thetext>*** Bug 174879 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-04-17 11:24:15 0000</bug_when>
            <thetext>alpha stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-04-17 11:25:48 0000</bug_when>
            <thetext>Ouch, forgot to take alpha out in the CC list. :( sorry</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2007-04-18 15:15:41 0000</bug_when>
            <thetext>ppc done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-18 15:30:54 0000</bug_when>
            <thetext>This one is ready for GLSA vote. I vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-04-23 14:17:54 0000</bug_when>
            <thetext>mips and arm? thanks! :)

security: SUSE and rPath have published announcements AFAICT.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2007-04-30 08:38:09 0000</bug_when>
            <thetext>voting yes too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-05-07 21:50:23 0000</bug_when>
            <thetext>GLSA 200705-07 is out, thanks to everybody</thetext>
          </long_desc>
      
    </bug>

</bugzilla>