Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 117560 - www-apps/phpBB-2.0.19 version bump
Summary: www-apps/phpBB-2.0.19 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All All
: High enhancement (vote)
Assignee: Gentoo Web Application Packages Maintainers
URL: http://www.phpbb.com/downloads.php
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-01-03 02:08 UTC by Michael Zanetta
Modified: 2006-01-04 06:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Zanetta 2006-01-03 02:08:33 UTC
Hello,

A new version of phpbb is available. It fixes 2 XSS vulns.
According to Secunia : http://secunia.com/product/463/#advisories_2005
There is still an unpatched vuln in it for the remote avatar information diclosure :
http://secunia.com/advisories/16868/

Maybe this one will be more secure than in the past.

BTW, will you provide an anonymous cvs access for the phpBB forum code used at forums.gentoo.org?

Thanks in advance,
Michael
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-01-03 02:12:28 UTC

*** This bug has been marked as a duplicate of 115908 ***
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-01-03 02:49:00 UTC
Security does not care; web-apps - bump if you wish...
Comment 3 Renat Lumpau (RETIRED) gentoo-dev 2006-01-03 03:11:46 UTC
2.0.19 in CVS.

Perhaps ping infra (tomk?) about forums.g.o?
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2006-01-03 04:55:42 UTC
tomk - ping ;)
Comment 5 Tom Knight (RETIRED) gentoo-dev 2006-01-03 05:11:26 UTC
Anoncvs is being worked on, not sure what the current status is. BTW 2.0.19 has a security bug which I raised with phpBB, they are going to fix it in their cvs (and I've fixed it in ours) but they won't release a new version because of it.
Comment 6 Renat Lumpau (RETIRED) gentoo-dev 2006-01-03 06:57:28 UTC
(In reply to comment #5)
> BTW 2.0.19 has
> a security bug which I raised with phpBB, they are going to fix it in their cvs
> (and I've fixed it in ours) but they won't release a new version because of it.

And then people ask us why it's masked.
Comment 7 Michael Zanetta 2006-01-03 07:03:04 UTC
(In reply to comment #5)
> Anoncvs is being worked on, not sure what the current status is. BTW 2.0.19 has
> a security bug which I raised with phpBB, they are going to fix it in their cvs
> (and I've fixed it in ours) but they won't release a new version because of it.
> 

I'll be much more confident by using your cvs version... can't wait for it to be up!
Thanks for the information. 
Comment 8 Michael Zanetta 2006-01-04 06:07:00 UTC
(In reply to comment #5)
> Anoncvs is being worked on, not sure what the current status is. BTW 2.0.19 has
> a security bug which I raised with phpBB, they are going to fix it in their cvs
> (and I've fixed it in ours) but they won't release a new version because of it.
> 

BTW, are there some snapshots available so it'll be quicker than searching for all
files that you've modified ?