Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 118891

Summary: GLSA 200502-08 applies to wrong packages
Product: Gentoo Security Reporter: Ian Stakenvicius <ian>
Component: GLSA ErrorsAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: pgsql-bugs
Priority: Lowest    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Ian Stakenvicius 2006-01-13 09:27:31 UTC
This GLSA says it applies to all packages older than 8.0.1, but postgresql says they've fixed the related bugs as follows:

CAN-2005-0227:  7.3.9+, 7.4.7+, 8.0.1+
CAN-2005-0244:  7.3.9+, 7.4.7+, 8.0.1+
CAN-2005-0245:  7.3.10+, 7.4.7+, 8.0.1+
CAN-2005-0246:  7.3.9+, 7.4.7+, 8.0.1+

Could this GLSA be updated to reflect that, so it doesn't keep saying that it still applies to these packages?
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-13 11:16:14 UTC
Please advise on what versions are affected by this.
Comment 2 Ian Stakenvicius 2006-01-13 11:25:39 UTC
I know for sure 7.4.8 is, and I'm assuming all .ebuilds with versions above and including those I listed (except 7.4.7 which is already explicitly excluded, and those above 8.0.1, to which this GLSA doesn't apply):

7.3.10, 7.3.11, 7.3.12, 7.3.13, 7.4.8, 7.4.9, 7.4.10, and 7.4.11

Note that some of these versions don't have ebuilds yet.

Note also that a similar thing applies to GLSA 200502-19 and GLSA 200505-12.  You can see what versions the fixes have been made to at http://www.postgresql.org/support/security.html
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-13 11:53:10 UTC
Sorry Ian, wasn't clear on that. Wanted Postgresql herd to advise and then we'll fix the advisory.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-25 13:24:36 UTC
Postgresql please advise.
Comment 5 Masatomo Nakano (RETIRED) gentoo-dev 2006-01-29 12:18:19 UTC
Sorry for being late!

Our latest versions are 7.3.11/7.4.9/8.0.4, which are not affected by the security problems.
Therefore, we should update the GLSA.
Comment 6 Ian Stakenvicius 2006-02-02 07:35:33 UTC
Hmm.  This may be a duplicate of bug #104682
Comment 7 Stefan Cornelius (RETIRED) gentoo-dev 2006-02-02 14:58:39 UTC

*** This bug has been marked as a duplicate of 104682 ***