Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 20075 - New version of http-fetcher released; also some url/email corrections for that package.
Summary: New version of http-fetcher released; also some url/email corrections for tha...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All All
: High normal
Assignee: Patrick Kursawe (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-04-27 18:54 UTC by Lyle Hanson
Modified: 2003-06-23 03:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lyle Hanson 2003-04-27 18:54:35 UTC
I am the author of the HTTP Fetcher project.  It's not clear to me who within
Gentoo is responsible for maintaining this or other ebuilds so I'm submitting
this bug report to inform you of some changes.

HTTP Fetcher 1.0.2 has been released, correcting the buffer overflow reported in
Gentoo Linux Security Announcement 200301-6 (in a more graceful,
functionality-preserving way than the patch implemented in http-fetcher-1.0.1-r1
that Gentoo currently runs) as well as some other fixes and improvements.  I
advise upgrading to this release.

Secondly, the package is listed under the net/www category.  Since it's not an
end-user application, I suggest moving it to dev/libs.

Last, the *.ebuild file(s) contains outdated URLs.  Corrections (I'm looking at
http-fetcher.1.0.1-r1.ebuild) should be:
* HOMEPAGE="http://http-fetcher.sourceforge.net"
* SRC_URI: not sure what format this should be in, looks like a regexp or a
variable substitution in this value.  The .tar.gz is hosted by SourceForge, the
link to the Minneapolis mirror would be:
http://prdownloads.sourceforge.net/http-fetcher/http_fetcher-1.0.2.tar.gz?use_mirror=umn

Feel free to contact me for any further info.  If there is another way I should
report these types of issues please let me know.

-Lyle Hanson

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Patrick Kursawe (RETIRED) gentoo-dev 2003-06-18 07:28:46 UTC
Sorry for the delay. We are just getting a maintainer system, so your bug report was just the correct way. I just committed 1.0.2 as ~x86, will change that to x86 in about a week (if I forget that, please remind me) - I will also request moving the package.
Comment 2 Patrick Kursawe (RETIRED) gentoo-dev 2003-06-18 07:29:21 UTC
Setting to TEST-REQUEST
Comment 3 Patrick Kursawe (RETIRED) gentoo-dev 2003-06-23 03:26:26 UTC
have to reopen...
Comment 4 Patrick Kursawe (RETIRED) gentoo-dev 2003-06-23 03:26:47 UTC
... in order to mark it "FIXED".