First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 188172
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matt Fleming (RETIRED) <mjf@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 188172 depends on: 170861 Show dependency tree
Bug 188172 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-08 20:42 0000
tetex needs updating because it includes vulnerable xpdf code. See bug 185225
for a patch.

------- Comment #1 From Matt Fleming (RETIRED) 2007-08-08 20:58:38 0000 -------
CC'ing maintainer and setting whiteboard status.

------- Comment #2 From Matt Fleming (RETIRED) 2007-08-08 21:17:51 0000 -------
Adding CVE number

------- Comment #3 From Robert Buchholz 2007-09-01 17:16:45 0000 -------
After talking to aballier, I just committed app-text/tetex-3.0_p1-r4 that
should fix this issue.

I also cleaned out old versions of tetex-3, but 2 probably still contains
vulnerable code. Pylon said he'd look into what needs 2.0 before that can be
cleaned out.

------- Comment #4 From Pierre-Yves Rofes 2007-09-22 14:14:01 0000 -------
any updates about the 2.x series?

------- Comment #5 From Robert Buchholz 2007-09-22 22:30:41 0000 -------
(In reply to comment #4)
> any updates about the 2.x series?

Not from me. Pylon, does anything still need it?

------- Comment #6 From Lars Weiler (RETIRED) 2007-09-23 21:42:00 0000 -------
> Not from me. Pylon, does anything still need it?

AFAIK we can clean out tetex-2 from the tree.  The only thing that holds us
back is stabilising some ebuilds.  Let me create a list tomorrow.

------- Comment #7 From Pierre-Yves Rofes 2007-09-27 17:46:28 0000 -------
(In reply to comment #6)
> > Not from me. Pylon, does anything still need it?
> 
> AFAIK we can clean out tetex-2 from the tree.  The only thing that holds us
> back is stabilising some ebuilds.  Let me create a list tomorrow.
> 
Ok, so I guess we can just mark > 3.0_p1-r4 as unaffected, and < vulnerable (so
including all 2.x series too, but since it will be removed soon it's no
problem). is it ok with you?

------- Comment #8 From Pierre-Yves Rofes 2007-09-28 08:52:43 0000 -------
GLSA 200707-17.

------- Comment #9 From Pierre-Yves Rofes 2007-09-28 08:54:14 0000 -------
(In reply to comment #8)
> GLSA 200707-17.
> 

hmm it was 200709-17, sorry :/

First Last Prev Next    No search results available      Search page      Enter new bug