First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 69658
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
ez-ipupdate-3.0.11_beta8-syslog.patch ez-ipupdate-3.0.11_beta8-syslog.patch patch solar 2004-11-01 06:59 0000 300 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 69658 depends on: Show dependency tree
Bug 69658 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-31 12:54 0000
Opening a bug so we can keep track of this issue. Klieber/Solar please provide
any further information/patches.

This is exploitable both in daemon and quiet mode.

------- Comment #1 From solar 2004-11-01 06:57:04 0000 -------
I have this ready to go. I'm itching to commit it please advise.

------- Comment #2 From solar 2004-11-01 06:59:33 0000 -------
Created an attachment (id=43073) [details]
ez-ipupdate-3.0.11_beta8-syslog.patch

patch that fixes format string problem in syslog code.

------- Comment #3 From solar 2004-11-01 07:02:36 0000 -------
Initial maintainer is no longer a dev.
Package has no clear maintainer.

What do we think about when we do sec updates for bugs and said pkg has no metadata.xml that we bring it up to the list that it has no maintainer and security@ requests that somebody || herd take XX under it's wing.

------- Comment #4 From Sune Kloppenborg Jeppesen 2004-11-01 07:07:45 0000 -------
Klieber/Solar: any news on coordinated release? All we have is:

> He will probably disclose this problem on Nov 3rd.

Nah, let's make that the 9th instead.

Wrt maintainers I think we should send a mail to see if anyone is willing to take it.

------- Comment #5 From solar 2004-11-01 08:14:49 0000 -------
No new news updates. Is the 9th ok with us? 
We were on the CC: so we should respond confirming the 9th is ok with us.

------- Comment #6 From solar 2004-11-01 09:05:28 0000 -------
- http://www.ez-ip.net/

EZ-IP closed to the general public...

Effective immediately, the EZ-IP project is closed to the general public. Preferred members will continue to have access to all EZ-IP services. This change in policy is the result of continued abuses on the part of "Free" account holders. We have enjoyed serving the community with this project over the past 8 months and are truly sorry that it has become necessary to close membership. Over the next few weeks, we will be revamping the EZ-IP site and application process to allow users to "upgrade" to Preferred Member status.
--------

Wonder who still needs this ebuild in portage? (argh I wish we could get stats from mirrors)

------- Comment #7 From Thierry Carrez (RETIRED) 2004-11-03 02:56:35 0000 -------
I vote to mask it (with no maintainer/ closed to the public reasons), first
step toward complete removal.

------- Comment #8 From Sune Kloppenborg Jeppesen 2004-11-04 11:42:29 0000 -------
I vote for masking. Is standard procedure to contact -dev first?

------- Comment #9 From Kurt Lieber 2004-11-04 11:54:50 0000 -------
standard procedure is sending an email to -dev saying "we want to mask this
package and here's why.  If nobody steps up to maintain it, it will be masked
in 24 hours"

I vote for masking as well, but if someone is willing to take it over, I see no
reason to mask it.

------- Comment #10 From solar 2004-11-06 06:49:03 0000 -------
I'd like to patch it on the 9th in case there any remaining gnetoo users who
use the service, before we outright decide to mask it. Then I'll vote for for
removal anytime after the 10th.

------- Comment #11 From Thierry Carrez (RETIRED) 2004-11-09 04:21:52 0000 -------
D Day. I think we should patch it now ?

------- Comment #12 From solar 2004-11-09 07:59:05 0000 -------
So ez-ipupdate goes right to stable? Or play the arch game?

------- Comment #13 From Chris White (RETIRED) 2004-11-09 08:11:16 0000 -------
I'd just stable move it, the patch is only one line and unless someone has a
broken syslog include file, it's gonna work.

------- Comment #14 From Rajiv Aaron Manglani 2004-11-09 08:11:51 0000 -------
with such a simple patch, i think this can go right to stable.

------- Comment #15 From solar 2004-11-09 08:14:52 0000 -------
Thanks that's what I wanted to know.
I'll remove the old cruft ez-ipupdate-3.0.11_beta8.ebuild so/if anybody takes this pkg on to maintain it they will atleast have a clean plate to start with. etc.. 

------- Comment #16 From solar 2004-11-09 08:19:42 0000 -------
ez-ipupdate-3.0.11_beta8-r1 is now in CVS

KEYWORDS="x86 ppc sparc amd64"

Opening bug.

------- Comment #17 From Philippe Weibel 2004-11-09 11:21:37 0000 -------
> Wonder who still needs this ebuild in portage?

from http://ez-ipupdate.com/:

ez-ipupdate is a small utility for updating your host name for the any of the dynamic DNS service offered at:

    * http://www.ez-ip.net
    * http://www.justlinux.com
    * http://www.dhs.org
    * http://www.dyndns.org
    * http://www.ods.org
    * http://gnudip.cheapnet.net (GNUDip)
    * http://www.dyn.ca (GNUDip)
    * http://www.tzo.com
    * http://www.easydns.com
    * http://www.dyns.cx
    * http://www.hn.org
    * http://www.zoneedit.com

... so this little utility can update to other services than just ez-ip. (I don't know it this URL is really the "official" one, or if there is still an official site / maintainer)

I use it for DynDNS.org and this tool is the best tool for IP udate for me (tried some others)

------- Comment #18 From Tuan Van (RETIRED) 2004-11-09 12:47:20 0000 -------
I use ez-ipupdate. It works for me for year (with dyndns.org). Please don't
remove it.

------- Comment #19 From Sune Kloppenborg Jeppesen 2004-11-11 07:11:18 0000 -------
GLSA 200411-20

First Last Prev Next    No search results available      Search page      Enter new bug