Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 933227 - [guru] www-apps/libmedium-20231020 misses package(s) in RDEPEND
Summary: [guru] www-apps/libmedium-20231020 misses package(s) in RDEPEND
Status: RESOLVED FIXED
Alias: None
Product: GURU
Classification: Unclassified
Component: Package issues (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: benoit.dufour
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: qa-guru
  Show dependency tree
 
Reported: 2024-05-31 06:41 UTC by Agostino Sarubbo
Modified: 2024-08-12 03:23 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
build.log (build.log,385.96 KB, text/plain)
2024-05-31 06:41 UTC, Agostino Sarubbo
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2024-05-31 06:41:40 UTC
https://blogs.gentoo.org/ago/2020/07/04/gentoo-tinderbox/

Issue: www-apps/libmedium-20231020 misses package(s) in RDEPEND.
Discovered on: amd64 (internal ref: guru_tinderbox)
System: GCC-14-SYSTEM (https://wiki.gentoo.org/wiki/Project:Tinderbox/Common_Issues_Helper#GCC-14)

Info about the issue:
https://wiki.gentoo.org/wiki/Project:Tinderbox/Common_Issues_Helper#QA0080
Comment 1 Agostino Sarubbo gentoo-dev 2024-05-31 06:41:42 UTC
Created attachment 894691 [details]
build.log

build log and emerge --info
Comment 2 benoit.dufour 2024-05-31 18:00:39 UTC
I won't fix it bug upstream fix those bugs:
cargo ebuild
Error: Found 3 vulnerabilities:

Crate:    h2
Version:  0.3.21
Title:    Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Date:     2024-01-17
ID:       RUSTSEC-2024-0003
URL:      https://rustsec.org/advisories/RUSTSEC-2024-0003
Solution: Upgrade to ^0.3.24 or >=0.4.2

Crate:    h2
Version:  0.3.21
Title:    Degradation of service in h2 servers with CONTINUATION Flood
Date:     2024-04-03
ID:       RUSTSEC-2024-0332
URL:      https://rustsec.org/advisories/RUSTSEC-2024-0332
Solution: Upgrade to ^0.3.26 or >=0.4.4

Crate:    mio
Version:  0.8.8
Title:    Tokens for named pipes may be delivered after deregistration
Date:     2024-03-04
ID:       RUSTSEC-2024-0019
URL:      https://rustsec.org/advisories/RUSTSEC-2024-0019
Solution: Upgrade to >=0.8.11

Please fix the issues or use "--noaudit" flag.