Bug 102374 - www-apps/egroupware XML-RPC Vulnerabilities round 2
Bug#: 102374 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: major Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: jaervosz@gentoo.org
Component: Vulnerabilities
URL: 
Summary: www-apps/egroupware XML-RPC Vulnerabilities round 2
Keywords:  
Status Whiteboard: B1 [glsa] jaervosz
Opened: 2005-08-13 07:29 0000
Description:   Opened: 2005-08-13 07:29 0000
see bug #102324

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-08-14 22:06:39 0000 -------
Now instead see bug #102576 

------- Comment #2 From Renat Lumpau 2005-08-16 12:18:44 0000 -------
egroupware-1.0.0.009 in CVS

------- Comment #3 From Sune Kloppenborg Jeppesen 2005-08-16 13:05:25 0000 -------
Arches please test and mark stable. 

------- Comment #4 From Michael Hanselmann (hansmi) (RETIRED) 2005-08-16 14:45:18 0000 -------
Stable on ppc.

------- Comment #5 From Renat Lumpau 2005-08-17 03:22:27 0000 -------
stable on x86

------- Comment #6 From Jose Luis Rivero (yoswink) 2005-08-20 10:43:23 0000 -------
egroupware-1.0.0.009 stable on alpha.

A little note for our web-apps maintainers:

During the configuration of egroupware it complains about the lack of the gd
library which is needed to show an especific type of diagrams.

Nothing in the ebuild seems to reflect this so, maybe include a USE flag called
 "diagrams" (or whatever) which enabled a RDEPEND on media-libs/gd could be good
idea. 

I think, something similiar happends with the imap extension.

Thanks.

------- Comment #7 From Renat Lumpau 2005-08-20 16:26:42 0000 -------
Could you post the errors you got?

------- Comment #8 From Jose Luis Rivero (yoswink) 2005-08-20 19:27:55 0000 -------
Sure:

If I run the checks in: /$egroupware-vdir/setup/check_install.php, it gives me
the following errors:

[*] Checking extension imap is loaded or loadable: False
The imap extension is needed by the two email apps (even if you use email with
pop3 as protocoll).

[*] Checking for GD support...: False
Your PHP installation does not have appropriate GD support. You need gd library
version 1.8 or newer to see Gantt charts in projects.

------- Comment #9 From Renat Lumpau 2005-08-21 10:31:50 0000 -------
Thanks

------- Comment #10 From Thierry Carrez (RETIRED) 2005-08-24 06:58:36 0000 -------
amd64: you're late to mark stable, GLSA waits.

------- Comment #11 From Homer Parker 2005-08-24 08:41:12 0000 -------
Stable on amd64, sorry for the delay

------- Comment #12 From Thierry Carrez (RETIRED) 2005-08-24 12:06:22 0000 -------
CVS says current keywords are :
KEYWORDS="alpha ~amd64 ~hppa ppc ~sparc x86"

hparker: apparently the keyword didn't make it to CVS.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-08-24 12:23:37 0000 -------
OK it's fixed now, ready for GLSa

------- Comment #14 From Thierry Carrez (RETIRED) 2005-08-24 12:58:27 0000 -------
GLSA 200508-14