<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>184592</bug_id>
          
          <creation_ts>2007-07-08 10:43 0000</creation_ts>
          <short_desc>dev-lang/erlang bundles internal zlib (CVE-2004-0797, CVE-2005-1849)</short_desc>
          <delta_ts>2007-07-24 11:32:04 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B3 [noglsa]</status_whiteboard>
          
          <priority>P1</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>fauli@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>emacs@gentoo.org</cc>
    
    <cc>lang-misc@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-07-08 10:43:31 0000</bug_when>
            <thetext>After becoming aware that erlang ships its internal copy of zlib (thanks to flameeyes), I checked the version included.  Current stable 11.2.1 has zlib 1.1.4 while the latest in testing (11.2.5) has 2.2.3 (current zlib).  Between that there have been fixed at least two security issues. 

See bug 99751 (A1) and bug 61749 (A3).  As zlib is patched, I cannot simply remove it and build against the system one, but upstream promised me to enable that in version 12. 

My proposal: Stabilise 11.2.5 immediately (no bug reports in the few days it has been in the tree).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-07-14 13:34:37 0000</bug_when>
            <thetext>Arches please stabilise dev-lang/erlang-11.2.5</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-07-15 22:01:23 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-07-17 21:47:56 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-07-18 05:48:26 0000</bug_when>
            <thetext>Changing status, as all arches are stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-18 06:07:13 0000</bug_when>
            <thetext>Thx Opfer.

I tend to vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ulm@gentoo.org</who>
            <bug_when>2007-07-18 06:43:36 0000</bug_when>
            <thetext>CVE-2005-1849 and CVE-2004-0797 from the two originally cited zlib bugs are both denial-of-service attacks which IMHO means that this one is severity B3.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-18 07:34:59 0000</bug_when>
            <thetext>Thanks Ulrich. I vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-07-24 10:56:47 0000</bug_when>
            <thetext>I vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-24 11:32:04 0000</bug_when>
            <thetext>closing without glsa then. Feel free to reopen if you disagree, as always :)</thetext>
          </long_desc>
      
    </bug>

</bugzilla>