Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 97655
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 97655 depends on: Show dependency tree
Bug 97655 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-07-01 13:42 0000
The pear command makes use of affected XML-RPC library.

php-4.4.0_rc2 is in the tree, but it's probably better to have a patched version of the current stable, which can be stableized faster.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-07-01 13:43:28 0000 -------
Rating B2 as it requires the unusual setup of having malicious PEAR servers to
connect to...

------- Comment #2 From Sebastian Bergmann (RETIRED) 2005-07-01 22:45:32 0000 -------
Maybe just adding

  RDEPEND=">=dev-php/PEAR-XML_RPC-1.3.1"

to the dev-php/php, dev-php/php-cgi, and dev-php/mod_php ebuilds does the trick.

------- Comment #3 From Thierry Carrez (RETIRED) 2005-07-08 01:51:40 0000 -------
php herd: your call... we are a little late already :)

------- Comment #4 From Thierry Carrez (RETIRED) 2005-07-11 06:15:36 0000 -------
PHP herd waits for php 4.4.0 final.

------- Comment #5 From Sebastian Bergmann (RETIRED) 2005-07-11 07:49:43 0000 -------
PHP 4.4.0 (final) is in the tree.

------- Comment #6 From Stefan Cornelius (RETIRED) 2005-07-11 18:19:14 0000 -------
Arches please test and mark 4.4.0 stable, thank you.

------- Comment #7 From Jason Wever (RETIRED) 2005-07-11 18:30:14 0000 -------
mod_php-4.4.0 has a dependency on >=net-www/apache-2.0.54-r10.  do we really
want this right now (as I belive this is one of the apache builds with the new
config)?

------- Comment #8 From Sebastian Bergmann (RETIRED) 2005-07-12 00:02:37 0000 -------
I am working on a new ebuild for mod_php-4.4.0 that is based on the current
mod_php-4.3.11 ebuild.

The current mod_php-4.4.0 ebuild will become mod_php-4.4.0-r1 and use the new
Apache layout.

------- Comment #9 From Sebastian Bergmann (RETIRED) 2005-07-12 02:15:07 0000 -------
Stable on x86.

------- Comment #10 From Gustavo Zacarias (RETIRED) 2005-07-12 08:54:51 0000 -------
sparc stable.

------- Comment #11 From Markus Rothe 2005-07-12 10:17:39 0000 -------
stable on ppc64

------- Comment #12 From Tobias Scherbaum 2005-07-12 12:27:00 0000 -------
ppc stable

------- Comment #13 From Stuart Herbert (RETIRED) 2005-07-13 09:13:17 0000 -------
ppc64: please stabilise php-cgi-4.4.0 as part of this bug.

General note: dev-php/php, dev-php/php-cgi and dev-php/mod_php packages always 
need stabilising at the same time.

Best regards,
Stu

------- Comment #14 From Bryan Østergaard (RETIRED) 2005-07-13 11:41:43 0000 -------
Stable on alpha + ia64.

------- Comment #15 From Markus Rothe 2005-07-13 12:55:34 0000 -------
stuart: we (ppc64) have never had an ebuild keyworded for the 4.x release
series. If you *realy want* this package stable on ppc64, I'm going to test it. :-)

------- Comment #16 From Thierry Carrez (RETIRED) 2005-07-14 03:38:35 0000 -------
php-cgi was never keyworded ppc64 so I guess it could stay that way.
That said, we are still missing a few keywords :

amd64: on php, mod_php and php-cgi 4.4.0
hppa: on php-cgi 4.4.0

------- Comment #17 From Luis Medinas (RETIRED) 2005-07-14 07:14:42 0000 -------
dev-php/php-4.4.0 dev-php/php-cgi-4.4.0 dev-php/mod_php-4.4.0-r1 tested in
amd64. Works fine.

------- Comment #18 From Simon Stelling (RETIRED) 2005-07-14 08:45:29 0000 -------
thanks, amd64 finally stable

------- Comment #19 From René Nussbaumer 2005-07-14 11:24:38 0000 -------
Thanks. Stable on hppa.

------- Comment #20 From Thierry Carrez (RETIRED) 2005-07-15 01:37:31 0000 -------
amd64 still misses php-cgi AFAICT...

------- Comment #21 From Simon Stelling (RETIRED) 2005-07-15 05:48:42 0000 -------
sorry, forgot about php-cgi... amd64 finally done.

------- Comment #22 From Thierry Carrez (RETIRED) 2005-07-15 07:59:16 0000 -------
GLSA 200507-15
mips, s390 should mark stable to benefit from GLSA

------- Comment #23 From Hardave Riar (RETIRED) 2005-07-23 22:31:21 0000 -------
Stable on mips.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug