Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 117560

Summary: www-apps/phpBB-2.0.19 version bump
Product: Gentoo Linux Reporter: Michael Zanetta <grimmlin>
Component: New packagesAssignee: Gentoo Web Application Packages Maintainers <web-apps>
Status: RESOLVED FIXED    
Severity: enhancement CC: tomk
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://www.phpbb.com/downloads.php
Whiteboard:
Package list:
Runtime testing required: ---

Description Michael Zanetta 2006-01-03 02:08:33 UTC
Hello,

A new version of phpbb is available. It fixes 2 XSS vulns.
According to Secunia : http://secunia.com/product/463/#advisories_2005
There is still an unpatched vuln in it for the remote avatar information diclosure :
http://secunia.com/advisories/16868/

Maybe this one will be more secure than in the past.

BTW, will you provide an anonymous cvs access for the phpBB forum code used at forums.gentoo.org?

Thanks in advance,
Michael
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-01-03 02:12:28 UTC

*** This bug has been marked as a duplicate of 115908 ***
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-01-03 02:49:00 UTC
Security does not care; web-apps - bump if you wish...
Comment 3 Renat Lumpau (RETIRED) gentoo-dev 2006-01-03 03:11:46 UTC
2.0.19 in CVS.

Perhaps ping infra (tomk?) about forums.g.o?
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2006-01-03 04:55:42 UTC
tomk - ping ;)
Comment 5 Tom Knight (RETIRED) gentoo-dev 2006-01-03 05:11:26 UTC
Anoncvs is being worked on, not sure what the current status is. BTW 2.0.19 has a security bug which I raised with phpBB, they are going to fix it in their cvs (and I've fixed it in ours) but they won't release a new version because of it.
Comment 6 Renat Lumpau (RETIRED) gentoo-dev 2006-01-03 06:57:28 UTC
(In reply to comment #5)
> BTW 2.0.19 has
> a security bug which I raised with phpBB, they are going to fix it in their cvs
> (and I've fixed it in ours) but they won't release a new version because of it.

And then people ask us why it's masked.
Comment 7 Michael Zanetta 2006-01-03 07:03:04 UTC
(In reply to comment #5)
> Anoncvs is being worked on, not sure what the current status is. BTW 2.0.19 has
> a security bug which I raised with phpBB, they are going to fix it in their cvs
> (and I've fixed it in ours) but they won't release a new version because of it.
> 

I'll be much more confident by using your cvs version... can't wait for it to be up!
Thanks for the information. 
Comment 8 Michael Zanetta 2006-01-04 06:07:00 UTC
(In reply to comment #5)
> Anoncvs is being worked on, not sure what the current status is. BTW 2.0.19 has
> a security bug which I raised with phpBB, they are going to fix it in their cvs
> (and I've fixed it in ours) but they won't release a new version because of it.
> 

BTW, are there some snapshots available so it'll be quicker than searching for all
files that you've modified ?