First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 147838
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
opera-9.02.ebuild opera 9.02 ebuild text/plain Eion Robb 2006-09-21 15:04 0000 4.33 KB Details
opera-9.02-install.patch opera 9.02 install patch patch Eion Robb 2006-09-21 15:04 0000 317 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 147838 depends on: 146702 Show dependency tree
Bug 147838 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-09-16 11:12 0000
According to this

------- Comment #1 From Carsten Lohrke 2006-09-16 11:12:31 0000 -------
According to this¹ site, Opera, similar to the recently fixed openssl and
mozilla packages, accepts faked ssl certificates as well.


[1] http://www.cdc.informatik.tu-darmstadt.de/securebrowser/

------- Comment #2 From Sune Kloppenborg Jeppesen 2006-09-17 07:31:33 0000 -------
This should be fixed in 9.02.

------- Comment #3 From Wolf Giesen (RETIRED) 2006-09-21 04:02:59 0000 -------
*** Bug 148489 has been marked as a duplicate of this bug. ***

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-09-21 04:11:17 0000 -------
Axxo, 9.02 is available. Please bump.

------- Comment #5 From Wolf Giesen (RETIRED) 2006-09-21 04:36:26 0000 -------
Huh, isn't that 9.02 RC2, still?

------- Comment #6 From Wolf Giesen (RETIRED) 2006-09-21 04:37:44 0000 -------
/me kicks squid :(

------- Comment #7 From Eion Robb 2006-09-21 15:04:13 0000 -------
Created an attachment (id=97697) [details]
opera 9.02 ebuild

------- Comment #8 From Eion Robb 2006-09-21 15:04:52 0000 -------
Created an attachment (id=97698) [details]
opera 9.02 install patch

put into files/ directory with ebuild

------- Comment #9 From Jeroen Roovers 2006-09-21 15:30:30 0000 -------
(In reply to comment #6)
> Created an attachment (id=97697) [edit] [details]
> opera 9.02 ebuild
> 

(In reply to comment #7)
> Created an attachment (id=97698) [edit] [details]
> opera 9.02 install patch
> 
> put into files/ directory with ebuild
> 

Sorry, both of you. As bug 146702 shows, the ebuild has been in the tree for a
few decaminutes and the stabilisation procedure has started. This bug depends
on the stabilisation bug.

------- Comment #10 From Jeroen Roovers 2006-09-23 08:57:29 0000 -------
www-client/opera-9.02 is stable on all arches.

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-09-23 09:51:35 0000 -------
This one is ready for GLSA vote.

------- Comment #12 From Tobias Scherbaum 2006-09-23 12:25:06 0000 -------
*cough* stabling of security bugs should be handled on the related security bug
report, not on other bug reports ...

------- Comment #13 From Sune Kloppenborg Jeppesen 2006-09-23 13:43:33 0000 -------
@Jeroen, Tobias is right. We usually mark stable on the security bug so arches
know what is up.

------- Comment #14 From Jeroen Roovers 2006-09-23 14:07:30 0000 -------
(In reply to comment #12)
> @Jeroen, Tobias is right. We usually mark stable on the security bug so arches
> know what is up.

Right. Could you point me toward the relevant documentation?

------- Comment #15 From Sune Kloppenborg Jeppesen 2006-09-23 22:23:39 0000 -------
http://www.gentoo.org/security/en/vulnerability-policy.xml
http://www.gentoo.org/security/en/coordinator_guide.xml

Only some parts of the GLSA Coordinator Guide are relevant.

If you have any questions just pop in #-security and ask.

Now back to bug voting :-)

------- Comment #16 From Matthias Geerdsen 2006-09-26 11:24:05 0000 -------
tending to vote yes

------- Comment #17 From Sune Kloppenborg Jeppesen 2006-09-26 13:06:14 0000 -------
Security please vote.

------- Comment #18 From Wolf Giesen (RETIRED) 2006-09-26 22:04:40 0000 -------
Since it contains a fix for the same problem as GLSA'd openssl/gnutls I say
YES.

------- Comment #19 From Sune Kloppenborg Jeppesen 2006-09-27 01:11:53 0000 -------
Voting YES. Let's have a GLSA.

------- Comment #20 From Matthias Geerdsen 2006-09-28 07:26:32 0000 -------
GLSA 200609-18

thanks everyone

First Last Prev Next    No search results available      Search page      Enter new bug