Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 189786

Summary: www-servers/lighttpd stable markings due to security cleanup
Product: Gentoo Linux Reporter: Thilo Bangert (RETIRED) (RETIRED) <bangert>
Component: New packagesAssignee: MIPS Porters <mips>
Status: RESOLVED FIXED    
Severity: normal CC: bangert, carenas
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 146062    

Description Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-08-22 07:01:12 UTC
as per bug #185442 lighttpd<1.4.16 has open security problems.

this is a heads up to ask the affected archs to 
please mark 1.4.16 stable, so that old versions can be removed.
Comment 1 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-08-22 07:03:07 UTC
cc affected archs

> this is a heads up to ask the affected archs to 
> please mark 1.4.16 stable, so that old versions can be removed.
Comment 2 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-08-26 08:33:44 UTC
only mips left. 30 days counting from the 22nd. thanks.

> this is a heads up to ask the affected archs to 
> please mark 1.4.16 stable, so that old versions can be removed.
Comment 3 Carlo Marcelo Arenas Belon 2007-09-10 03:30:48 UTC
stabilization should be most likely done with 1.4.18 instead as explained in bug #191912
Comment 4 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-10-12 14:11:25 UTC
first round of removals done.
arm, sh and mips: please mark lighttpd-1.4.18 stable - security see bug #191912
Comment 5 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-10-12 14:12:37 UTC
> arm, sh and mips: please mark lighttpd-1.4.18 stable - security see bug #191912
Comment 6 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2007-10-12 14:13:48 UTC
sorry for the spam.... me fighting the arch box

> arm, sh and mips: please mark lighttpd-1.4.18 stable - security see bug #191912
Comment 7 Antti Järvinen 2007-11-16 10:21:02 UTC
lighttpd-1.4.18 compiles and runs fine on my Silicon Graphics O2 mips box.

System uname: 2.6.19-rc5-o2 mips64 R5000 V2.1  FPU V1.0
CFLAGS="-march=r5000 -O2 -pipe -mabi=32"
CHOST="mips-unknown-linux-gnu"

The older 1.3 version didn't compile at all at first, because it required automake-1.7, which it of course didn't depend on. In my opinion the old 1.3 series should be dropped and the 1.4.18 be marked stable for mips.
Comment 8 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2008-01-04 22:40:58 UTC
Antti Järvinen: perhaps you want to become an arch tester for the mips arch?! the mips team, it appears, is in need for people with access to the right hardware.

thanks
Thilo
Comment 9 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2008-01-19 00:40:21 UTC
MIPS please.
Comment 10 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2008-02-12 23:03:06 UTC
Closing wrt http://www.gentoo.org/news/20080210-mips-experimental-arch.xml

removing vulnerable ebuild now.