Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 751091 - <app-shells/mcfly-0.5.3: depends on vulnerable linked-hash-map crate
Summary: <app-shells/mcfly-0.5.3: depends on vulnerable linked-hash-map crate
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://rustsec.org/advisories/RUSTSE...
Whiteboard: ~4 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2020-10-25 01:51 UTC by John Helmert III
Modified: 2021-02-28 16:35 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-10-25 01:51:27 UTC
See $URL for details. Maintainer(s), please advise if this package uses this package in a way that could trigger these vulnerabilities.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-10-25 01:59:47 UTC
Looks like the dependency is on 0.5.3 on master.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-17 21:26:54 UTC
Maintainer, please cleanup potentially vulnerable versions.
Comment 3 Larry the Git Cow gentoo-dev 2021-02-28 09:03:18 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a00881bec58afbe2eba620be35549d52e3d162df

commit a00881bec58afbe2eba620be35549d52e3d162df
Author:     Michael Mair-Keimberger <mmk@levelnine.at>
AuthorDate: 2021-02-20 09:37:32 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-02-28 09:03:07 +0000

    app-shells/mcfly: security cleanup
    
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Michael Mair-Keimberger <mmk@levelnine.at>
    Bug: https://bugs.gentoo.org/751091
    Closes: https://github.com/gentoo/gentoo/pull/19555
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 app-shells/mcfly/Manifest           |  51 ------------------
 app-shells/mcfly/mcfly-0.3.6.ebuild |  96 ---------------------------------
 app-shells/mcfly/mcfly-0.5.2.ebuild | 104 ------------------------------------
 app-shells/mcfly/mcfly-0.5.3.ebuild | 104 ------------------------------------
 4 files changed, 355 deletions(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-28 16:35:57 UTC
Thank you! All done.