<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>198385</bug_id>
          
          <creation_ts>2007-11-07 17:47 0000</creation_ts>
          <short_desc>x11-libs/goffice &lt;0.3.7 Multiple issues in embedded PCRE</short_desc>
          <delta_ts>2009-03-16 11:04:39 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/27543/</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>156984</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>esigra@gmail.com</cc>
    
    <cc>gnome-office@gentoo.org</cc>
    
    <cc>sum.notify@gmail.com</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-07 17:47:34 0000</bug_when>
            <thetext>goffice ships a copy of PCRE which is be vulnerable to several security issues as pointed out in bug #198198.

PCRE 7.3 fixes the issues mentioned. goffice 0.2.1  (current stable) ships version 6.3 of PCRE. 

According to the ChangeLog goffice 0.3.7 requires uses the system PCRE.

Gnome-office, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-07 17:48:39 0000</bug_when>
            <thetext>See bug 156984.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-20 00:46:49 0000</bug_when>
            <thetext>Gnome-office, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eva@gentoo.org</who>
            <bug_when>2007-11-21 22:08:19 0000</bug_when>
            <thetext>per bug #191555, gnumeric can&apos;t use newer versions of goffice (limited to &lt;0.3)
we could put newer releases of gnumeric but they are still considered development release. A 1.7.90 is out since yesterday so the stable release shouldn&apos;t be too far from now.

@gnome-office, per the above paragraph, what&apos;s the best course of action ? I can take care of bumping gnumeric and goffice if needed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dang@gentoo.org</who>
            <bug_when>2007-11-29 03:30:33 0000</bug_when>
            <thetext>Ubuntu ships 1.7.11 in gutsy, so I&apos;d say put a 1.7 version in the tree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-04 01:15:46 0000</bug_when>
            <thetext>ping.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eva@gentoo.org</who>
            <bug_when>2007-12-10 00:18:27 0000</bug_when>
            <thetext>00:23 &lt; EvaSDK&gt; dang: hey, just so you know, I haven&apos;t commited work on goffice 
                bug because the goffice/gnumeric bump doesn&apos;t work yet
00:24 &lt; EvaSDK&gt; latest tests tend to show that goffice-0.4.3 doesn&apos;t export all 
                required symbol to let gnumeric-1.7.12 (last release to work 
                with 0.4) compile
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eva@gentoo.org</who>
            <bug_when>2007-12-10 23:19:08 0000</bug_when>
            <thetext>I&apos;ve pushed the work on goffice slots into CVS. I hope I didn&apos;t break anything and will check tomorrow morning on a &quot;clean&quot; box .

All apps besides gnumeric should already have relevant version checks thanks to RobbieAB (on #-desktop). If anyone can/want to do gnumeric just ping me, I couldn&apos;t make gnumeric-1.7.12 compile for me yet, and I&apos;m not sure we want a dev release for goffice 0.5 and gnumeric-1.7.9* in tree just yet (and I&apos;m pretty busy irl these days).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eva@gentoo.org</who>
            <bug_when>2008-01-01 18:55:00 0000</bug_when>
            <thetext>hi security, ebuilds needed to close this bug are finally in the tree.

you&apos;ll need to get goffice-0.4, goffice-0.6 and gnumeric-1.8 before when can ditch goffice-0.2</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-01 22:16:22 0000</bug_when>
            <thetext>[23:11] &lt;rbu&gt; EvaSDK: do i understand right we need both goffice 0.4.3 and 0.6.1 to be stable?
[23:11] &lt;EvaSDK&gt; rbu: afaik, not everything is compatible with goffice-0.6
[23:11] &lt;EvaSDK&gt; abiword-plugins and gnumeric compile against 0.6
[23:12] &lt;EvaSDK&gt; but it seems gnucash doesn&apos;t know about 0.6 yet

Arches, please test and mark stable x11-libs/goffice-0.4.3, x11-libs/goffice-0.6.1 and app-office/gnumeric-1.8.0.
Target keywords : &quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-01-02 00:22:57 0000</bug_when>
            <thetext>OK took care of goffice-1.4  but bumped into a configure error with -1.6 on both ppc64 and ppc.  

checking for GNOME... yes
checking for GOFFICE... configure: error: Package requirements (
        glib-2.0                &gt;= 2.8.0
        gobject-2.0             &gt;= 2.6.3
        gmodule-2.0             &gt;= 2.6.3
        libgsf-1                &gt;= 1.13.3
        libxml-2.0              &gt;= 2.4.12
        pango                   &gt;= 1.8.1
        pangocairo              &gt;= 1.8.1
        libart-2.0              &gt;= 2.3.11
        cairo                   &gt;= 1.2.0
        cairo-svg               &gt;= 1.2.0
        cairo-pdf               &gt;= 1.2.0
        cairo-ps                &gt;= 1.2.0
 
        gtk+-2.0                &gt;= 2.6.0
        libglade-2.0            &gt;= 2.3.6
 
        gconf-2.0
        libgnomeui-2.0          &gt;= 2.0.0
        libgsf-gnome-1          &gt;= 1.12.2
) were not met:

No package &apos;cairo-svg&apos; found

How do you guys want to deal with this?  I assume this is x11-libs/libsvg-cairo ?  </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>compnerd@gentoo.org</who>
            <bug_when>2008-01-02 01:35:31 0000</bug_when>
            <thetext>Yeap, needs a built_with_use which I added.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-01-02 06:14:04 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-01-02 10:17:44 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2008-01-02 10:20:08 0000</bug_when>
            <thetext>*** Bug 204018 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-01-02 14:29:42 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-01-02 17:11:01 0000</bug_when>
            <thetext>ppc and ppc64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2008-01-10 19:41:29 0000</bug_when>
            <thetext>amd64 done, apologies about the delay.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-01-10 19:53:08 0000</bug_when>
            <thetext>glsa request filed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2008-01-10 20:13:02 0000</bug_when>
            <thetext>This is how keywords look in tree now,

gnumeric-1.6.3.ebuild:KEYWORDS=&quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86&quot;
gnumeric-1.8.0.ebuild:KEYWORDS=&quot;alpha amd64 ~hppa ia64 ppc ppc64 sparc x86&quot;

Did hppa miss it?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-01-11 13:08:22 0000</bug_when>
            <thetext>...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-01-30 22:44:27 0000</bug_when>
            <thetext>GLSA 200801-19, sorry for the delay.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>