Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 132749
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jérôme Poulin <jeromepoulin@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
emech-3.0.2.ebuild Bump with segfault fixed and uptime + dns USE flags. text/plain Jérôme Poulin 2006-05-08 19:36 0000 1.64 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 132749 depends on: Show dependency tree
Bug 132749 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-08 19:32 0000
There was a security update which was just fixed about the bot segfaulting when
it receives an empty CTCP in NOTICE and it would be important to update the
ebuild ASAP, I also added 2 USE flags for 'uptime' reports and raw 'dns'
resolving support which should not be activated all the time.

------- Comment #1 From Jérôme Poulin 2006-05-08 19:36:15 0000 -------
Created an attachment (id=86455) [details]
Bump with segfault fixed and uptime + dns USE flags.

------- Comment #2 From Jakub Moc (RETIRED) 2006-05-09 00:00:19 0000 -------
Does security want this? Looks like a good way to DoS the thing to me... ;)

------- Comment #3 From Jérôme Poulin 2006-06-05 19:47:20 0000 -------
Let's move on! It's been here for a while and did not even make its way to
portage yet. (Did I misset severity to minor?)

------- Comment #4 From Raphael Marichez 2006-06-11 14:04:41 0000 -------
Hi IRC team, emech seems to have a security issue, please bump an updated
ebuild.

Jakub: thanks
J

------- Comment #5 From Raphael Marichez 2006-06-11 14:04:41 0000 -------
Hi IRC team, emech seems to have a security issue, please bump an updated
ebuild.

Jakub: thanks
Jérome: désolé pour le lag :/ . La sévérité est effectivement "minor" :)


From http://www.energymech.net/ :
"EnergyMech 3.0.2
Contains a critical bugfix. Yes we're still alive. Download it now "

------- Comment #6 From Alec Warner 2006-06-11 17:51:05 0000 -------
revbumped, security, you need anything else?

------- Comment #7 From Raphael Marichez 2006-06-12 02:48:48 0000 -------
Thanks Antarus.
(Whereas i'm not sure that the 2.x branch is affected.)

x86 & ppc, please mark 3.0.2 stable, thanks in advance

------- Comment #8 From Jérôme Poulin 2006-06-13 16:35:55 0000 -------
Just seen the new ebuild version pop-up in portage but still does not contains
the 'uptime' and 'dns' use flags to allow disabling uptime reports and raw dns
resolving, not everyone wants that and I would consider important adding those
too. The eBuild I attached is a modified version which only adds those two
flags. Thanks.

------- Comment #9 From Tobias Scherbaum 2006-06-14 11:21:48 0000 -------
ppc stable

------- Comment #10 From Sune Kloppenborg Jeppesen 2006-06-16 11:19:48 0000 -------
Seems misplaced in auditing and fixing status whiteboard.

x86 please test and mark stable if possible.

------- Comment #11 From Joshua Jackson 2006-06-21 19:32:48 0000 -------
x86 done

------- Comment #12 From Sune Kloppenborg Jeppesen 2006-06-22 05:42:54 0000 -------
Time for GLSA vote. I tend to vote NO.

------- Comment #13 From Wolf Giesen (RETIRED) 2006-06-22 05:45:14 0000 -------
Can't be sure without the source, but from "empty CTCP" I'd vote another "no".

------- Comment #14 From Raphael Marichez 2006-06-22 05:51:46 0000 -------
i vote yes :

1. to send an empty CTCP is trivial;

2. it's very worrying for the user (it's not like a Xine DoS: on IRC, you could
be banned or akilled if you're rejoining too often. And it pollutes the logs);

3. and many IRC users love to play such stupid games.

------- Comment #15 From Thierry Carrez (RETIRED) 2006-06-22 10:19:42 0000 -------
I vote YES. DoS on IRC is evil :)

------- Comment #16 From Sune Kloppenborg Jeppesen 2006-06-22 11:16:01 0000 -------
Ok, lets have a GLSA.

------- Comment #17 From Thierry Carrez (RETIRED) 2006-06-26 12:27:13 0000 -------
Sent as GLSA 200606-26

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug