Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 103295

Summary: New ebuild : sugarcrm
Product: Gentoo Linux Reporter: Tomoyuki Sakurai (RETIRED) <trombik>
Component: New packagesAssignee: Default Assignee for New Packages <maintainer-wanted>
Status: RESOLVED FIXED    
Severity: enhancement CC: andreis.vinogradovs, eddymul, jesse, luis, m.kefeder, mettlerd, steeeeeveee, xenoterracide
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.sugarforge.org/
Whiteboard:
Package list:
Runtime testing required: ---
Attachments: the ebuild
files/fix_perm.sh
www-apps/sugarcrm/sugarcrm-4.0.0.ebuild
www-apps/sugarcrm/files/postinstall-en.txt
sugarcrm-4.5.1.ebuild
sugarcrm-5.0.0g-r1.ebuild
5.2.0e ebuild version
sugarcrm-5.5.0_beta1.ebuild
ugarcrm-5.5.0_beta1 ebuild
ru languares files
SugarCRM 5.5 ebuild
Fixed .htaccess privileges
sugarcrm-5.5.0.ebuild
rc2 version 6.0 ebuild - please, only for testing
sugarcrm-6.0.0.ebuild
sugarcrm-5.5.4.ebuild
sugarcrm-6.4.0

Description Tomoyuki Sakurai (RETIRED) gentoo-dev 2005-08-21 16:43:25 UTC
from the website:
"SugarCRM is a suite of business automation tools for managing your marketing,
sales and customer service operations."

here is my alpha version ebuild of sugarcrm.
since I don't fully understand the concept behind webapp.eclass, any advice
would be appreciated.

have fun!
Comment 1 Tomoyuki Sakurai (RETIRED) gentoo-dev 2005-08-21 16:44:23 UTC
Created attachment 66509 [details]
the ebuild
Comment 2 Tomoyuki Sakurai (RETIRED) gentoo-dev 2005-08-21 16:45:34 UTC
Created attachment 66510 [details]
files/fix_perm.sh

chown -R hack
Comment 3 Chris White (RETIRED) gentoo-dev 2005-08-21 18:48:47 UTC
Yay for more trombik ebuilds :). 
Comment 4 Chris White (RETIRED) gentoo-dev 2005-09-03 01:36:18 UTC
Accepting now that I've written the webapp.eclass doc and have something solid 
to work with :P. 
Comment 5 steveb 2005-12-17 04:15:08 UTC
Created attachment 74930 [details]
www-apps/sugarcrm/sugarcrm-4.0.0.ebuild

My version/release of the SugarCRM ebuild for SugarCRM 4.0.0
Comment 6 steveb 2005-12-17 04:15:48 UTC
Created attachment 74931 [details]
www-apps/sugarcrm/files/postinstall-en.txt

postinstall-en.txt for the SugarCRM 4.0.0 ebuild
Comment 7 Gunnar Wrobel (RETIRED) gentoo-dev 2005-12-19 08:03:18 UTC
Thanks Steve!

sugarcrm is now in our unofficial overlay:
http://svn.gnqs.org/projects/gentoo-webapps-overlay/browser/experimental/www-apps/sugarcrm/

Please note that the overlay is unofficial, not a Gentoo project, and not
supported. It is intended to provide easier access to new web applications.


Comment 8 Renat Lumpau (RETIRED) gentoo-dev 2005-12-19 08:05:24 UTC
upstream
Comment 9 Jakub Moc (RETIRED) gentoo-dev 2006-03-06 02:03:19 UTC
*** Bug 125181 has been marked as a duplicate of this bug. ***
Comment 10 Jakub Moc (RETIRED) gentoo-dev 2007-01-22 21:29:08 UTC
*** Bug 163329 has been marked as a duplicate of this bug. ***
Comment 11 Mike Bonar 2007-03-04 04:44:56 UTC
Created attachment 112012 [details]
sugarcrm-4.5.1.ebuild

Created new ebuild for sugarCRM
Comment 12 Caleb Cushing 2007-06-11 13:07:55 UTC
any reason 4.5 never made it into the overlay?
Comment 13 Caleb Cushing 2007-06-11 13:30:40 UTC
haha... there's a missing dependendancy in the 4.5.1 ebuild. it needs to pull in app-arch/unzip...
Comment 14 Jesse Adelman 2008-01-14 20:40:47 UTC
Uh, will this ever get to Portage? Thanks. :)
Comment 15 luis 2008-06-01 22:17:01 UTC
Hello, 

Any plan to make this available in gentoo ?
Comment 16 Andreis Vinogradovs ( slepnoga ) 2008-08-10 05:15:59 UTC
Created attachment 162601 [details]
sugarcrm-5.0.0g-r1.ebuild

Version bump
Comment 17 Jeroen Roovers (RETIRED) gentoo-dev 2008-09-22 02:09:39 UTC
*** Bug 238167 has been marked as a duplicate of this bug. ***
Comment 18 Peter Alfredsen (RETIRED) gentoo-dev 2009-02-13 05:57:06 UTC
Re-opening. This apparently never got anywhere.
Comment 19 Peter Alfredsen (RETIRED) gentoo-dev 2009-02-13 05:58:44 UTC
*** Bug 258809 has been marked as a duplicate of this bug. ***
Comment 20 Andreis Vinogradovs ( slepnoga ) 2009-06-02 07:21:42 UTC
Created attachment 193247 [details]
5.2.0e ebuild  version 

Upstream relesed 5.2.0 version.
Ebuild version bump and EAPI=2 support
Comment 21 Andreis Vinogradovs ( slepnoga ) 2009-06-07 15:50:16 UTC
Created attachment 193812 [details]
sugarcrm-5.5.0_beta1.ebuild

This is alpha ebuild
Comment 22 Andreis Vinogradovs ( slepnoga ) 2009-07-25 11:45:00 UTC
Created attachment 199109 [details]
ugarcrm-5.5.0_beta1 ebuild

MSSQL and Oracle database server supported
Comment 23 Andreis Vinogradovs ( slepnoga ) 2009-07-25 11:45:56 UTC
Created attachment 199111 [details]
ru languares files
Comment 24 Andreis Vinogradovs ( slepnoga ) 2009-07-28 19:04:23 UTC
Now ebuild added to rion overlay.
Comment 25 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-27 20:42:23 UTC
There has been a vulnerability report for sugarcrm:
Name:      CVE-2009-2978
URL:       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2978
Published: 2009-08-27

SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and
earlier, and 5.2.0g and earlier, allows remote attackers to execute
arbitrary SQL commands via unspecified vectors.

Please consider updating the package in overlays it is currently in. Please note that the initial importer to the official Portage tree must verify that the issue is fixed. If you have any questions, please contact the Security Team.
Comment 26 Andreis Vinogradovs ( slepnoga ) 2009-09-28 11:31:50 UTC
(In reply to comment #25)

> 
> Please consider updating the package in overlays it is currently in. Please
> note that the initial importer to the official Portage tree must verify that
> the issue is fixed. If you have any questions, please contact the Security
> Team.
> 

only 5.5.0_beta2 version in rion.
Comment 27 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-11-27 10:22:57 UTC
There has been a vulnerability report for sugarcrm:
http://secunia.com/advisories/37464/

Janek Vind has reported some vulnerabilities in SugarCRM, which can be exploited by malicious users to conduct SQL injection attacks, bypass certain security restrictions, and compromise a vulnerable system.

For more information visit the URL above.

Solution:
Update to version 5.2.0k.
The vulnerabilities are also addressed in version 5.5.0.RC4.
Comment 28 Andreis Vinogradovs ( slepnoga ) 2009-11-27 12:04:20 UTC
(In reply to comment #27)
> There has been a vulnerability report for sugarcrm:
> http://secunia.com/advisories/37464/
> 
> Janek Vind has reported some vulnerabilities in SugarCRM, which can be
> exploited by malicious users to conduct SQL injection attacks, bypass certain
> security restrictions, and compromise a vulnerable system.
> 
> For more information visit the URL above.
> 
> Solution:
> Update to version 5.2.0k.
> The vulnerabilities are also addressed in version 5.5.0.RC4.
> 

Tnx. foe you report 
Comment 29 Mikko Husari 2009-12-09 11:13:25 UTC
Created attachment 212527 [details]
SugarCRM 5.5 ebuild

I made copy of the beta build and twisted some of the things to fit 5.5.0
Comment 30 Mikko Husari 2009-12-09 12:17:17 UTC
Created attachment 212528 [details]
Fixed .htaccess privileges

Better version :)
Comment 31 Andreis Vinogradovs ( slepnoga ) 2009-12-09 16:58:22 UTC
Created attachment 212557 [details]
sugarcrm-5.5.0.ebuild

fixed dependency
Comment 32 Andreis Vinogradovs ( slepnoga ) 2009-12-09 16:59:10 UTC
Comment on attachment 212557 [details]
sugarcrm-5.5.0.ebuild

fixed dependency
Comment 33 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-03-27 20:18:34 UTC
There has been a vulnerability report for this package:

Name:      CVE-2010-0465
URL:       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0465
Published: 2010-03-19
Severity:  Medium
Description: 

Cross-site scripting (XSS) vulnerability in the online Documents
functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a
allows remote authenticated users to inject arbitrary web script or
HTML via the Document Name field.
Comment 34 Andreis Vinogradovs ( slepnoga ) 2010-07-05 05:19:50 UTC
Created attachment 237527 [details]
rc2 version 6.0 ebuild - please, only for testing
Comment 35 Andreis Vinogradovs ( slepnoga ) 2010-10-11 13:04:45 UTC
Created attachment 250219 [details]
sugarcrm-6.0.0.ebuild
Comment 36 Andreis Vinogradovs ( slepnoga ) 2010-10-11 13:05:50 UTC
Created attachment 250221 [details]
sugarcrm-5.5.4.ebuild
Comment 37 Andreis Vinogradovs ( slepnoga ) 2012-02-24 15:17:10 UTC
Created attachment 303067 [details]
sugarcrm-6.4.0
Comment 38 Maxim Koltsov (RETIRED) gentoo-dev 2012-02-25 14:30:32 UTC
It's finally done, thanks.