| Summary: | dev-util/cscope install includes insecure web frontend | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | SpanKY <vapier> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | minor | CC: | emacs, vim |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | All | ||
| Whiteboard: | B4 [noglsa] | ||
| Package list: | Runtime testing required: | --- | |
| Bug Depends on: | 160559 | ||
| Bug Blocks: | |||
|
Description
SpanKY
2006-12-22 07:03:30 UTC
Security, you want the web frontend removed or the big warning? I will inform upstream about the issue. I think a warning would be sufficient. 15.6-r1 with the warning in CVS now, security you now may cc arches if you think that it is needed, or close the bug. Security, all necessary steps from maintainers have been done. What will happen here next? (In reply to comment #4) > Security, all necessary steps from maintainers have been done. What will > happen here next? > The end of the known universe :) alpha amd64 arm ia64 mips s390 : please test and mark stable cscope-15.6-r1, thanks. hppa, ppc, ppc64, sparc, x86, please test and mark stable cscope-15.6-r1 if everything is OK. That is a very weak security issue, so if something is wrong with it, it should be better to stay with 15.5.20060927-r1 and to patch it with the warning in it. Forgot to add arches. And reassigning. "alpha amd64 arm ia64 mips s390 : please test and mark stable cscope-15.6-r1, thanks. hppa, ppc, ppc64, sparc, x86, please test and mark stable cscope-15.6-r1 if everything is OK. That is a very weak security issue, so if something is wrong with it, it should be better to stay with 15.5.20060927-r1 and to patch it with the warning in it." x86 stable ppc stable stable on hppa sparc stable. Stable on Alpha. amd64 stable ppc64 stable I would vote for NOglsa also vote NO Stable on MIPS. Closing. Security hasn't finished its procedure. yes, thanks. But noone will vote except me and tavis, so closing without glsa. Feel free to rereopen if you disagree :) |