Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 591010 - <www-client/links-2.14: Unix domain sockets shared between anonymous and non-anonymous instances
Summary: <www-client/links-2.14: Unix domain sockets shared between anonymous and non-...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: A4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-11 07:51 UTC by Agostino Sarubbo
Modified: 2017-05-27 09:18 UTC (History)
1 user (show)

See Also:
Package list:
=www-client/links-2.14
Runtime testing required: ---
kensington: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-08-11 07:51:27 UTC
From ${URL} :

Links 2.13 was released fixing one security issue.

Security bug fixed: Use separate unix domain socket for anonymous instances, so that the anonymous 
instance won't connect to non-anonymous one.

External References:

http://links.twibright.com/download/ChangeLog


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2016-12-08 02:31:30 UTC
@ Maintainer(s): Can we stabilize =www-client/links-2.14?
Comment 2 Patrice Clement gentoo-dev 2016-12-08 22:34:53 UTC
Go for it!
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2016-12-08 22:58:09 UTC
@ Arches,

please test and mark stable: =www-client/links-2.14
Comment 4 Tobias Klausmann (RETIRED) gentoo-dev 2016-12-12 15:58:00 UTC
Stable on alpha.
Comment 5 Agostino Sarubbo gentoo-dev 2016-12-13 11:05:47 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2016-12-13 11:31:14 UTC
x86 stable
Comment 7 Markus Meier gentoo-dev 2016-12-17 15:26:50 UTC
arm stable
Comment 8 Agostino Sarubbo gentoo-dev 2016-12-19 14:37:24 UTC
sparc stable
Comment 9 Agostino Sarubbo gentoo-dev 2016-12-19 15:14:15 UTC
ia64 stable
Comment 10 Agostino Sarubbo gentoo-dev 2016-12-20 09:46:49 UTC
ppc stable
Comment 11 Agostino Sarubbo gentoo-dev 2016-12-22 09:36:50 UTC
ppc64 stable
Comment 12 Jeroen Roovers (RETIRED) gentoo-dev 2017-01-21 12:30:25 UTC
Stable for HPPA.
Comment 13 Yury German Gentoo Infrastructure gentoo-dev 2017-04-30 18:46:32 UTC
Maintainer(s), please drop the vulnerable version(s).
Comment 14 Yury German Gentoo Infrastructure gentoo-dev 2017-05-26 23:52:45 UTC
Maintainer(s), please drop the vulnerable version(s).
Comment 15 Patrice Clement gentoo-dev 2017-05-27 06:42:40 UTC
commit 29f45024cb3a319cee081556d5312bf3cf7e912f (HEAD -> master, origin/master, origin/HEAD)
Author:     Patrice Clement <monsieurp@gentoo.org>
AuthorDate: Sat May 27 08:22:23 2017 +0200
Commit:     Patrice Clement <monsieurp@gentoo.org>
CommitDate: Sat May 27 08:22:23 2017 +0200

www-client/links: remove vulnerable versions.

Gentoo-Bug: https://bugs.gentoo.org/591010

Package-Manager: Portage-2.3.3, Repoman-2.3.1

www-client/links/Manifest             |   2 -
www-client/links/links-2.12-r2.ebuild | 130 --------------------------------
www-client/links/links-2.12-r3.ebuild | 135 ---------------------------------
www-client/links/links-2.13.ebuild    | 136 ----------------------------------
4 files changed, 403 deletions(-)
delete mode 100644 www-client/links/links-2.12-r2.ebuild
delete mode 100644 www-client/links/links-2.12-r3.ebuild
delete mode 100644 www-client/links/links-2.13.ebuild
Comment 16 Thomas Deutschmann (RETIRED) gentoo-dev 2017-05-27 09:18:39 UTC
Downgraded to A4.

Repository is clean, all done.


@ Arches and Maintainer(s): Thank you for your work.