Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 194287 - dev-lang/anubis ships vulnerable version of libssl and libcrypto
Summary: dev-lang/anubis ships vulnerable version of libssl and libcrypto
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~ [masked]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-30 15:55 UTC by Samuli Suominen (RETIRED)
Modified: 2008-01-07 14:11 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Samuli Suominen (RETIRED) gentoo-dev 2007-09-30 15:55:21 UTC
dev-lang/anubis is a binary only software with no new releases and no maintainer in gentoo. it needs lib{ssl,crypto}.so.0.9.7 which it shipped with it as binary form also..

security, please advise should we (treecleaners) mask it for removal.
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-10-02 21:05:48 UTC
is there some kind of equivalent of this package in our tree?
In any case, binary only means there's nothing we can do about it...
Has upstream been contacted about this? Seems it's a french team, I can try to contact them to expose the problem and see what they say. I guess it's not much work to use external openssl/libcrypto...
Comment 2 Samuli Suominen (RETIRED) gentoo-dev 2007-10-08 15:37:19 UTC
I've mailed upstream, no response yet and I've also masked it for time being,

# Samuli Suominen <drac@gentoo.org> (08 Oct 2007)
# Binary only package shipping vulnerable OpenSSL and links against
# it. Masked for removal, unless upstream releases a new version 
# or provides us with source. Bug 194287.
dev-lang/anubis
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2007-10-08 18:18:24 UTC
Upstream responded as following:

<snip>

Hi, 

Thank you very much for your mail. Right now Anubis language is link against the OpenSSL 0.9.8b. We will update the package of Anubis language 1.7.0.1 to 0.9.8e as soon as possible. And for the new version 1.8.x still in beta test, we try to make an external link only. Because the programmers of Anubis has not so much time, we please you to wait less than one week for an update of that package.

Best regards

David RENE
Anubis Team Manager

</snip>

waiting then..
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-06 19:42:18 UTC
setting to enhancement as it's p.masked, ping back when upstream releases a fixed version.
Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2008-01-07 14:11:42 UTC
(In reply to comment #4)
> setting to enhancement as it's p.masked, ping back when upstream releases a
> fixed version.
> 

they didn't and I've punted the thing from tree