Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 42963 - <app-admin/msyslog-1.09d - buffer overflows on prior version
Summary: <app-admin/msyslog-1.09d - buffer overflows on prior version
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Highest enhancement (vote)
Assignee: Gentoo Security
URL: http://sourceforge.net/forum/forum.ph...
Whiteboard: B1 [ebuild+ masked]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-02-26 00:07 UTC by klavs klavsen
Modified: 2011-10-30 22:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description klavs klavsen 2004-02-26 00:07:48 UTC
check the link - msyslog package needs to be updated to 1.09d (it's 1.09a which (probably because of security) isn't even in the files list anymore).

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Tim Yamin (RETIRED) gentoo-dev 2004-03-18 10:00:54 UTC
Testing new Bugzilla flags; please ignore the spam...
Comment 2 Tim Yamin (RETIRED) gentoo-dev 2004-03-18 10:11:34 UTC
Testing new Bugzilla flags; please ignore the spam...
Comment 3 Tim Yamin (RETIRED) gentoo-dev 2004-03-18 10:13:46 UTC
Bugzilla flags: everything seems to work. Sorry for the spam.
Comment 4 Kurt Lieber (RETIRED) gentoo-dev 2004-04-06 08:59:54 UTC
aliz -- you were the last person to do any non-keywording work on this ebuild.  Can you bump the ebuild in portage?
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2004-04-07 08:25:31 UTC
Not ready for GLSA yet, ebuild must be bumped before. Setting component back to Security.

-K
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2004-04-13 03:15:31 UTC
Still needing a version bump to 1.09d. I did not find metadata to name a herd for this one, so it's still yours, aliz :)

-K
Comment 7 solar (RETIRED) gentoo-dev 2004-04-26 12:37:35 UTC
Quote from sourceforge site.

"There are buffer overflows on prior versions, update ASAP.
This vuln was reported & fixed by jkohen@
Advisory from CoreST coming."

Not a quick bump ;/
.ebuild needs a rewrite.

Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2004-05-04 07:31:09 UTC
If we can't find someone to maintain it, we should probably mask this one ?

-K
Comment 9 klavs klavsen 2004-05-04 08:52:45 UTC
No vulnerable versions should be in portage IMHO - or perhaps a "security mask" should be invented (if one is not forthcoming with the new GLSA integration) - so people with legitimate reasons to install vulnerable software can still install it - but people running ~x86 don't just get it (and think it's masked for the usual reasons - such as unstable ebuild etc.).

I switched to syslog-ng - its sooo much better :)
Comment 10 Kurt Lieber (RETIRED) gentoo-dev 2004-05-11 08:36:53 UTC
no maintainer for this package.  masking for now.
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2004-06-05 03:31:24 UTC
Status/severity update for masked ebuild
Comment 12 Joshua J. Berry (CondorDes) (RETIRED) gentoo-dev 2004-06-08 12:28:55 UTC
klieber and I discussed this briefly on IRC, and decided that this should be completely removed from Portage.  It's been masked for a while, nobody has complained, and we can't find a maintainer for it.

Once this is done we can close the bug.
Comment 13 Kurt Lieber (RETIRED) gentoo-dev 2004-06-29 13:31:15 UTC
removed from portage.  closing bug.