Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 672436 - GLSA 201812-01 marks latest dev-lang/php-7.1.24 as vulnerable
Summary: GLSA 201812-01 marks latest dev-lang/php-7.1.24 as vulnerable
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: GLSA Errors (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-12-03 05:13 UTC by Tomáš Mózes
Modified: 2018-12-03 20:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tomáš Mózes 2018-12-03 05:13:58 UTC
# qlist -Ic dev-lang/php
dev-lang/php 7.1.24

# glsa-check -v -t all
This system is affected by the following GLSAs:
[A] means this GLSA was marked as applied (injected),
[U] means the system is not affected and
[N] indicates that the system might be affected.

201812-01 [N] [local, remote] PHP: Multiple vulnerabilities ( dev-lang/php-7.1.24 )
Comment 1 Tomáš Mózes 2018-12-03 05:22:21 UTC
This seems to work:
      <unaffected range="ge" slot="5.6">5.6.38</unaffected>
      <unaffected range="ge" slot="7.0">7.0.32</unaffected>
      <unaffected range="ge" slot="7.1">7.1.22</unaffected>
      <unaffected range="ge" slot="7.2">7.2.10</unaffected>
      <vulnerable range="lt" slot="5.6">5.6.38</vulnerable>
      <vulnerable range="lt" slot="7.0">7.0.32</vulnerable>
      <vulnerable range="lt" slot="7.1">7.1.22</vulnerable>
      <vulnerable range="lt" slot="7.2">7.2.10</vulnerable>
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-12-03 19:06:48 UTC
(In reply to Tomáš Mózes from comment #1)
> This seems to work:
>       <unaffected range="ge" slot="5.6">5.6.38</unaffected>
>       <unaffected range="ge" slot="7.0">7.0.32</unaffected>
>       <unaffected range="ge" slot="7.1">7.1.22</unaffected>
>       <unaffected range="ge" slot="7.2">7.2.10</unaffected>
>       <vulnerable range="lt" slot="5.6">5.6.38</vulnerable>
>       <vulnerable range="lt" slot="7.0">7.0.32</vulnerable>
>       <vulnerable range="lt" slot="7.1">7.1.22</vulnerable>
>       <vulnerable range="lt" slot="7.2">7.2.10</vulnerable>

Fixed... sorry about that.
Comment 3 Tomáš Mózes 2018-12-03 20:35:28 UTC
Thanks Aaron.