Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 150294
Alias:
Product:
Component:
Status: RESOLVED
Resolution: INVALID
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matt Drew <aetius@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 150294 depends on: Show dependency tree
Bug 150294 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-10-06 08:51 0000
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286
https://issues.rpath.com/browse/RPL-680

The Red Hat bug is x86_64, but the rpath bug doesn't report platform and the
CVE links to several advisories that update all platforms (Mandriva, for
instance).

This is an old bug that just popped up again on fulldiclosure, I searched up
and down in bugzilla but didn't see it.  We still have vulnerable versions in
portage (see bug #140490, security cleanup needed).  Current stable is 249,
which fixes this particular problem.

------- Comment #1 From Matthias Geerdsen 2006-10-11 06:18:14 0000 -------
Thanks for the report.

Since the stable version is not affected and has been stable for months, this
does not appear to be worth a GLSA anymore.
The older versions are also vulnerable to a different issue, so they really
should be removed when possible, but this is handled in bug #140490.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug