<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>28220</bug_id>
          
          <creation_ts>2003-09-08 15:37 0000</creation_ts>
          <short_desc>security upd.: kdbg 1.2.9.ebuild</short_desc>
          <delta_ts>2003-09-15 23:49:24 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>KDE</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <keywords>EBUILD</keywords>
          <priority>P2</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>kde@gentoo.org</assigned_to>
          <cc>pythonhead@gentoo.org</cc>
    
    <cc>security@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2003-09-08 15:37:53 0000</bug_when>
            <thetext>Security Release Note:  Fixed the security flaw which version 1.2.8 was supposed
to, but did not, fix. The flaw enables any other local user to gain the
privileges of the user running KDbg provided the other users can access the
directory of the program being debugged. All versions of KDbg from 1.1.8 to
1.2.8, inclusive, including all development versions, are vulnerable. 
(copied from apps.kde.com)

What&apos;s the gentoo policy - is KDE 2.x still supported? I&apos;m asking, because the
ebuild could support it, but I don&apos;t know how to do this. need-kde() doesn&apos;t
support something like &gt;=2 and the kde-functions.eclass doesn&apos;t export
kde[minor/major] versions as distutils.eclass with $PYVER. btw.: Shouldn&apos;t be
there a eclass variable naming agreement? $PYVER_MAJOR &amp; $KDEMAJORVER isn&apos;t
consistent.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2003-09-08 15:38:25 0000</bug_when>
            <thetext>Created an attachment (id=17288)
kdbg-1.2.9.ebuild
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2003-09-08 16:51:37 0000</bug_when>
            <thetext>Dan: added you, because you are the author of kde-functions.eclass</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2003-09-09 07:07:26 0000</bug_when>
            <thetext>Adding security so that they can file a GLSA if they deem it appropriate. 
 
Removing dan since he doesn&apos;t want bugs assigned to him anymore. 
 
The ebuild has been added - waiting for security team to make a move before resolving the 
bug. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2003-09-09 08:23:33 0000</bug_when>
            <thetext>Caleb: Sorry, I didn&apos;t know that Dan don&apos;t want to get bugs assigned. The questions remain...

- is KDE 2.x still supported?
- how about kde-functions.eclass / KDE version export - should I file an extra bug report? e.g. In #27401 I worked around this, comparing $KDEDIR with a hardcoded path, to distinct between KDE 3 and 3.x. But that&apos;s the way it should work. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2003-09-09 08:31:10 0000</bug_when>
            <thetext>We are not supporting kde 2 and only leaving it available in portage for posterity.  I haven&apos;t 
been applying security fixes for it either.  I suppose it will be taken out in the next few 
months. 
 
As far as the second part goes, I don&apos;t have a good answer.  Your hacked solution in the 
pykde ebuild probably isn&apos;t the best, but if it works I say it&apos;s okay.  If we need to make 
changes to the eclass, go ahead and file another bug. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2003-09-15 19:36:12 0000</bug_when>
            <thetext>this ebuild has been put in portage. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2003-09-15 19:36:34 0000</bug_when>
            <thetext>*** Bug 28153 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>17288</attachid>
            <date>2003-09-08 15:38 0000</date>
            <desc>kdbg-1.2.9.ebuild</desc>
            <filename>kdbg-1.2.9.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDAzIEdlbnRvbyBUZWNobm9sb2dpZXMsIEluYy4KIyBEaXN0cmli
dXRlZCB1bmRlciB0aGUgdGVybXMgb2YgdGhlIEdOVSBHZW5lcmFsIFB1YmxpYyBMaWNlbnNlIHYy
CiMgJEhlYWRlcjogJAoKaW5oZXJpdCBrZGUKCm5lZWQta2RlIDMKCklVU0U9IiIKREVTQ1JJUFRJ
T049IkEgR3JhcGhpY2FsIERlYnVnZ2VyIEludGVyZmFjZSB0byBnZGIiClNSQ19VUkk9Im1pcnJv
cjovL3NvdXJjZWZvcmdlL2tkYmcvJHtQfS50YXIuZ3oiCkhPTUVQQUdFPSJodHRwOi8vbWVtYmVy
cy5uZXh0cmEuYXQvam9oc2l4dC9rZGJnLmh0bWwiCgojbXljb25mPSIke215Y29uZn0gLS13aXRo
LWtkZS12ZXJzaW9uPTMiCgojZXhwb3J0IExJQlFUTVQ9Ii1scXQtbXQiCgpMSUNFTlNFPSJHUEwt
MiIKS0VZV09SRFM9Ing4NiB+c3BhcmMgIH5wcGMiCgpSREVQRU5EPSI+PXN5cy1kZXZlbC9nZGIt
NS4wIg==
</data>        

          </attachment>
    </bug>

</bugzilla>