Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 140509 - app-editors/gedit, gnome-base/gdm - security cleanup needed
Summary: app-editors/gedit, gnome-base/gdm - security cleanup needed
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Linux Gnome Desktop Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-07-15 08:53 UTC by Jakub Moc (RETIRED)
Modified: 2006-11-04 21:06 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jakub Moc (RETIRED) gentoo-dev 2006-07-15 08:53:32 UTC
app-editors/gedit-0.9.6-r1: vulnerable via glsa(200506-09) ( ver < 2.10.3 ), affects ('ppc', 'sparc', 'x86')

gnome-base/gdm-2.2.5.4-r5: vulnerable via glsa(200606-14) ( ver < 2.8.0.8 ), affects ('ppc', 'sparc', 'x86')
gnome-base/gdm-2.8.0.7: vulnerable via glsa(200606-14) ( ver < 2.8.0.8 ), affects ('alpha', 'amd64', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 'sparc', 'x86')
gnome-base/gdm-2.8.0.7-r1: vulnerable via glsa(200606-14) ( ver < 2.8.0.8 ), affects ('alpha', 'amd64', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 'sparc', 'x86')

~gdm-2.8.0.7 still needs to stay unfortunately, until ia64 stabilizes gdm-2.8.0.8  wrt Bug 135027. CCing them.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-07-15 11:50:45 UTC
Also a Gnome thing:

media-libs/gdk-pixbuf-0.22.0-r3: vulnerable via glsa(200511-14) ( ver-rev < 0.22.0-r5 ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 'sh', 'sparc', 'x86')
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-10-20 02:57:33 UTC
vulnerable media-libs/gdk-pixbuf gone; the rest is still sitting there...
Comment 3 Mart Raudsepp gentoo-dev 2006-11-01 02:39:44 UTC
<app-editors/gedit-2.14.3 and <gnome-base/gdm-2.14.9 went the way of the do-do.
Only some cloning from DNA could bring them back now.
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2006-11-03 04:11:23 UTC
Hmmm, looks like a more thorough cleanup is needed - basically gnome-1* needs to die... yay, *plop* :)

gnome-base/gnome-1.4-r3 (depends on the removed gdm)

gnome-base/gnome-applets-1.4.0.5
gnome-base/nautilus-1.0.6-r10
x11-wm/sawfish-1.0.1-r6

(all RDEPENDS of gnome-base/gnome-1.4-r3)

plus all the stuff that becomes useless after punting the above.
Comment 5 Mart Raudsepp gentoo-dev 2006-11-04 21:06:56 UTC
gnome1 removed. I already removed gnome-2.12 due to matching gdm going away, but apparently didn't think of gnome1.4
Other stuff is the ongoing effort of purging gnome1 from the tree, which compnerd has been doing, and I intend to help. Closing bug.