Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 408887 - [security issue] [CVE-2011-2895] please version bump freebsd-ubin-8.2-r1
Summary: [security issue] [CVE-2011-2895] please version bump freebsd-ubin-8.2-r1
Status: RESOLVED FIXED
Alias: None
Product: Gentoo/Alt
Classification: Unclassified
Component: FreeBSD (show other bugs)
Hardware: All FreeBSD
: Normal normal (vote)
Assignee: Gentoo/BSD Team
URL: http://security.freebsd.org/advisorie...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-03-19 16:35 UTC by Yuta SATOH
Modified: 2012-04-02 10:28 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Yuta SATOH 2012-03-19 16:35:47 UTC
Title is all.
Details, please see URL.


Reproducible: Always
Comment 1 Yuta SATOH 2012-03-19 16:41:36 UTC
I think it's okay with only patches for usr.bin/compress/zopen.c from this result.

# equery b compress
sys-freebsd/freebsd-ubin-9.0 (/usr/bin/compress)

# equery b gzip
app-arch/gzip-1.4 (/bin/gzip)
Comment 2 Alexis Ballier gentoo-dev 2012-03-19 19:11:47 UTC
9.0 is fixed afaik
Comment 3 Yuta SATOH 2012-03-19 19:33:55 UTC
(In reply to comment #2)
> 9.0 is fixed afaik

Yes. I know about it.
However, I think freebsd-*-8.2 packages are included in official portage tree yet, and we need to provide security updates.

Thanks in advance.
Comment 4 Alexis Ballier gentoo-dev 2012-03-19 21:12:38 UTC
(In reply to comment #3)
> (In reply to comment #2)
> > 9.0 is fixed afaik
> 
> Yes. I know about it.
> However, I think freebsd-*-8.2 packages are included in official portage
> tree yet, and we need to provide security updates.
> 
> Thanks in advance.

or build 9.0 stages and deprecate older versions and remove them some time later :)

anyway, i dont have any <9.0 installs anymore, so i cant do it
Comment 5 Naohiro Aota gentoo-dev 2012-04-02 10:28:51 UTC
+*freebsd-ubin-8.2-r1 (02 Apr 2012)
+
+  02 Apr 2012; Naohiro Aota <naota@gentoo.org>
+  +files/freebsd-ubin-8.2-compress.patch, +freebsd-ubin-8.2-r1.ebuild,
+  -freebsd-ubin-8.2.ebuild:
+  Add patch to fix CVE-2011-2895. #408887
+