<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>198053</bug_id>
          
          <creation_ts>2007-11-04 13:33 0000</creation_ts>
          <short_desc>GLSA 200710-12 applies to stable media-libs/t1lib</short_desc>
          <delta_ts>2007-11-08 06:43:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>GLSA Errors</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>INVALID</resolution>
          
          <status_whiteboard>jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rich0@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>fonts@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rich0@gentoo.org</who>
            <bug_when>2007-11-04 13:33:25 0000</bug_when>
            <thetext>GLSA 200710-12 is listed as applying to media-libs/t1lib &lt; 5.0.2-r1.

However, version 1.3.1 is still in portage and has numerous dependencies.

If it is vulnerable then it needs to be fixed.  If it is not vulnerable then the GLSA should be patched so that it doesn&apos;t come up as a false alarm.

Do we need to add to the glsa?:
&lt;unaffected range=&quot;lt&quot;&gt;5.0&lt;/unaffected&gt;


Reproducible: Always</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-11-05 08:03:10 0000</bug_when>
            <thetext>fonts please advise wether 1.3.1 is affected?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-11-07 20:13:18 0000</bug_when>
            <thetext>The same code is present in t1lib-1.3.1. Do we have anything depending on the old version?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dirtyepic@gentoo.org</who>
            <bug_when>2007-11-08 04:34:48 0000</bug_when>
            <thetext>No, it doesn&apos;t look like it.  I&apos;ve masked it for removal.

dirtyepic@tycho ~ $ qgrep -N t1lib-1
app-misc/gfontview-0.5.0-r6:DEPEND=&quot;&gt;=media-libs/t1lib-1.0.1
app-text/xdvik-22.40y-r2:DEPEND=&quot;&gt;=media-libs/t1lib-1.3
media-gfx/swftools-0.7.0:DEPEND=&quot;&gt;=media-libs/t1lib-1.3.1
media-gfx/swftools-0.8.0:DEPEND=&quot;&gt;=media-libs/t1lib-1.3.1
media-gfx/swftools-0.8.1:DEPEND=&quot;&gt;=media-libs/t1lib-1.3.1
media-libs/t1lib-1.3.1:# $Header: /var/cvsroot/gentoo-x86/media-libs/t1lib/t1lib-1.3.1.ebuild,v 1.29 2007/01/05 08:35:17 flameeyes Exp $
sci-visualization/grace-5.1.20: &gt;=media-libs/t1lib-1.3.1
sci-visualization/grace-5.1.21: &gt;=media-libs/t1lib-1.3.1
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-11-08 06:43:02 0000</bug_when>
            <thetext>Thanks Ryan and Richard.

I&apos;ll close this one as INVALID since we don&apos;t have a policy regarding older vulnerable versions in the tree.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>