Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 102375 - www-apps/b2evolution XML-RPC Vulnerabilities round 2
Summary: www-apps/b2evolution XML-RPC Vulnerabilities round 2
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-08-13 07:32 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-08-24 21:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-13 07:32:02 UTC
see bug #102324
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-14 22:06:07 UTC
Now instead see bug #102576 
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-08-21 08:24:57 UTC
Nothing yet from upstream.
http://forums.b2evolution.net/viewtopic.php?t=5082
Comment 3 Stuart Herbert (RETIRED) gentoo-dev 2005-08-23 00:45:01 UTC
Hi,

b2evo is used on Gentoo infrastructure.  Has anyone made sure that infra has
been alerted to this problem, and that they have taken the appropriate measures?

Best regards,
Stu
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-08-23 00:58:50 UTC
I've posted an alert on #gentoo-infra and a privmsg to dsd a few days ago. No
clue if this has been fixed yet. They might miss an easy patch solution... and
this is one is nowhere as easy as the previous one to adapt to each separate
XML-RPC lib version.
Comment 5 Daniel Drake (RETIRED) gentoo-dev 2005-08-23 01:06:12 UTC
Yes, xmlrpc.php has been removed for now
Comment 6 Stuart Herbert (RETIRED) gentoo-dev 2005-08-23 05:46:59 UTC
:)  Thanks for the confirmation on that.

I hope to get an updated package into Portage asap.

Best regards,
Stu
Comment 7 Stuart Herbert (RETIRED) gentoo-dev 2005-08-24 00:40:41 UTC
Hi,

I've created a b2evolution-0.9.0.12-r1 package, which replaces the bundled
xmlrpc library with the patched version.  I can't test it from where I am today,
but as it is a straight drop-in, it should work.

Best regards,
Stu
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2005-08-24 01:33:40 UTC
Please let us know when it's committed.
Comment 9 Stuart Herbert (RETIRED) gentoo-dev 2005-08-24 14:27:39 UTC
Erm, the bump was committed this morning, before I posted comment #7 :)
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-24 21:45:04 UTC
Thx Stuart.  
 
Closing without GLSA.