Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 552566 - =dev-java/httpcomponents-client-4.5: stabilisation request
Summary: =dev-java/httpcomponents-client-4.5: stabilisation request
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Java (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Java team
URL: http://hc.apache.org/httpcomponents-c...
Whiteboard:
Keywords: STABLEREQ
Depends on: 553210 553234
Blocks: CVE-2014-3577
  Show dependency tree
 
Reported: 2015-06-19 17:16 UTC by Patrice Clement (RETIRED)
Modified: 2015-06-26 07:20 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Patrice Clement (RETIRED) gentoo-dev 2015-06-19 17:16:26 UTC
Following bug 520200 and version bump of httpcomponents-core, we need to version bump httpcomponentns-client to its latest iteration. Sec team will ask up to clean up vulnerable versions after stabilisation will be done. As far as httpcomponents-client-4.3.1 go, it doesn't build against 4.4. Which means it is a blocking bug.

Reproducible: Always
Comment 1 Patrice Clement (RETIRED) gentoo-dev 2015-06-24 19:12:20 UTC
+*httpcomponents-client-4.5 (24 Jun 2015)
+
+  24 Jun 2015; Patrice Clement <monsieurp@gentoo.org>
+  +files/httpcomponents-client-fluent-hc-4.5-build.xml,
+  +files/httpcomponents-client-httpclient-4.5-build.xml,
+  +files/httpcomponents-client-httpclient-cache-4.5-build.xml,
+  +files/httpcomponents-client-httpclient-osgi-4.5-build.xml,
+  +files/httpcomponents-client-httpmime-4.5-build.xml,
+  +httpcomponents-client-4.5.ebuild:
+  Version bump. Fix bug 552566.
+

Phew!

Arch teams,

This is an urgent request. We need to clean up httpcomponents-client-4.3.1-r1 since it has a dependency on a vulnerable version of httpcomponents-core.

Please stabilise:
=dev-java/httpcomponents-client-4.5.ebuild

Target arches:
amd64 x86

Thanks!
Comment 2 Agostino Sarubbo gentoo-dev 2015-06-26 07:19:55 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2015-06-26 07:20:07 UTC
x86 stable. Closing.