Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 115851

Summary: app-office/{koffice,kword}|kde-base/{kpdf,kdegraphics}: another round of xpdf patches
Product: Gentoo Security Reporter: Carsten Lohrke (RETIRED) <carlo>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: cryos
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A2 [glsa] jaervosz
Package list:
Runtime testing required: ---
Attachments:
Description Flags
post-1.3-koffice-CAN-2005-3193.diff (updated)
none
post-3.4.3-kdegraphics-CAN-2005-3193.diff (updated)
none
kword-1.4.2-r6.ebuild
none
koffice-1.4.2-r6.ebuild
none
kdegraphics-3.4.3-r3.ebuild
none
kpdf-3.4.3-r3.ebuild none

Description Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:50:45 UTC
vendor-sec restricted... *gasp*
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:52:41 UTC
Created attachment 74936 [details, diff]
post-1.3-koffice-CAN-2005-3193.diff (updated)
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:54:20 UTC
Created attachment 74937 [details, diff]
post-3.4.3-kdegraphics-CAN-2005-3193.diff (updated)
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:55:21 UTC
Created attachment 74938 [details]
kword-1.4.2-r6.ebuild
Comment 4 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:56:03 UTC
Created attachment 74939 [details]
koffice-1.4.2-r6.ebuild
Comment 5 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:56:49 UTC
Created attachment 74940 [details]
kdegraphics-3.4.3-r3.ebuild
Comment 6 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 05:57:44 UTC
Created attachment 74941 [details]
kpdf-3.4.3-r3.ebuild
Comment 7 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-17 06:05:12 UTC
Guys, please test if you have some time left, but the patches should apply cleanly anyways.
Comment 8 Jeffrey Forman (RETIRED) gentoo-dev 2005-12-17 06:16:43 UTC
Quick change of platform in bugzilla. Sorry about the email.
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-12-17 06:23:56 UTC
no release date yet.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-17 12:04:22 UTC
Thx carlo. Are these patches fetched from upstream public svn?
Comment 11 Markus Rothe (RETIRED) gentoo-dev 2005-12-17 13:43:01 UTC
PPC64 good: all four packages build and run fine with patches being applied.

there is no testcase, is there?
Comment 12 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-12-17 14:39:15 UTC
Looks good on hppa and ppc.
Comment 13 Mark Loeser (RETIRED) gentoo-dev 2005-12-17 23:41:17 UTC
Looks good on x86
Comment 14 Jason Wever (RETIRED) gentoo-dev 2005-12-18 09:39:38 UTC
Did any of you who successfully built koffice have postgres support enabled?  I got what looked like a parallel make build failure the first time (second attempt is running as we speak)?

All of the others build find on SPARC
Comment 15 Marcus D. Hanwell (RETIRED) gentoo-dev 2005-12-18 10:36:50 UTC
Looks good on amd64. If there are any test cases I would be happy to test but no problems compiling or using the apps as normal. Didn't notice any parallel build issues but I don't have postgres support on this system.
Comment 16 Jason Wever (RETIRED) gentoo-dev 2005-12-18 13:57:32 UTC
koffice built correctly the second time around
Comment 17 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-20 06:25:48 UTC
(In reply to comment #10)
> Thx carlo. Are these patches fetched from upstream public svn?
> 

The patches are made by Dirk Mueller and made available via the kde-packager mailing list, but the code is in svn as well - so I am free to commit!?


(In reply to comment #14)
> Did any of you who successfully built koffice have postgres support enabled?  I
> got what looked like a parallel make build failure the first time (second
> attempt is running as we speak)?

I do, but only -j2, so it's not that likely I catch such an issue.


(In reply to comment #15)
> Looks good on amd64. If there are any test cases I would be happy to test but
> no problems compiling or using the apps as normal.

At least none available to me and I'm too lazy to create one.
Comment 18 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-20 08:05:18 UTC
Carlo, if the code is in public svn you are free to commit, but only mention the bug number and this bug will stay restricted until the issue is public.
Comment 19 Carsten Lohrke (RETIRED) gentoo-dev 2005-12-20 09:48:07 UTC
O.k. Knock on wood, that this is the last xpdf issue for at least a year.

<<< koffice-1.4.2-r6.ebuild
<<< kword-1.4.2-r6.ebuild

<<< kdegraphics-3.4.3-r3.ebuild
<<< kpdf-3.4.3-r3.ebuild
Comment 20 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-20 10:53:05 UTC
Thx Carlo. I only think it is reasonable to believe that this is the last round at least this year:-)

Arch Security Liaisons please test and mark stable. Only mention bug number so far.
Comment 21 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-12-20 11:48:37 UTC
ppc done
Comment 22 Mark Loeser (RETIRED) gentoo-dev 2005-12-20 12:25:18 UTC
x86 done
Comment 23 Marcus D. Hanwell (RETIRED) gentoo-dev 2005-12-20 12:38:38 UTC
Stable on amd64 too.
Comment 24 Markus Rothe (RETIRED) gentoo-dev 2005-12-20 12:47:58 UTC
stable on ppc64
Comment 25 Jason Wever (RETIRED) gentoo-dev 2005-12-21 06:03:35 UTC
SPARCy SPARC and the stable bunch
Comment 26 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-12-23 19:54:17 UTC
stable on alpha
Comment 27 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-03 07:51:16 UTC
Opening.
Comment 28 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-04 23:22:22 UTC
GLSA 200601-02