Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 90296 - net-libs/gecko-sdk: 1.7.7 might include security fixes
Summary: net-libs/gecko-sdk: 1.7.7 might include security fixes
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2? [ebuild+] koon
Keywords:
Depends on:
Blocks:
 
Reported: 2005-04-24 15:10 UTC by Xake
Modified: 2005-05-13 01:58 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Xake 2005-04-24 15:10:43 UTC
Latest gecko-sdk in portage == 1.7.5
latest stable mozilla in portage == 1.7.7

If a version of mozilla is considered stable why is not the gecko-sdk made up from the same mozilla-version?

And a for me more intresting question: If mozilla bumps due to security, is there no chance that those securityholes within mozilla forcing the bump also may be securityholes within gecko-sdk?
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-04-25 01:50:45 UTC
It obviously depends on the security issues... Pure gecko things like buffer overflows in rendering or image loading would certainly be affected. Javascript privilege escalations are a little less obvious... In all cases, better safe than sorry.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-04-28 09:35:38 UTC
Moz team, please bump to 1.7.7
Comment 3 Joe Jezak (RETIRED) gentoo-dev 2005-05-05 16:17:41 UTC
GeckoSDK doesn't actually contain the gecko rendering engine, it only includes the files needed to build applications that link to the engine.  This includes a few programs for parsing idl files and librarys to allow XPCom linking.

The 1.7.5 version in portage is already using 1.7.6 internally to fix compile problems with mozilla, but I didn't bump the version number as there wouldn't be a reason for someone to want to recompile all of mozilla for an updated version of the SDK.  Unless the security issue is with LibXPCom, I don't think it's worth bumping the version number to force a recompile.

If someone on the security or Mozilla team feels otherwise, I'd be happy to do it.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-05-13 01:58:13 UTC
Then it's INVALID as a security bug. It may be reopened as a bump request assigned to maintainer, though.