Summary: | dev-scheme/chicken < 3.1.0 Multiple issues in embedded PCRE | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | fauli, scheme |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://secunia.com/advisories/27543/ | ||
Whiteboard: | B2? [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Robert Buchholz (RETIRED)
2007-11-12 22:42:10 UTC
Upstream has included new unaffected libpcre in their recent releases, but those don't build at this time. I've discussed with Robert and decided to package mask the current versions. Hopefully we'll have a new version available soon. I've just committed chicken-2.731. The problem was with portage exporting O, which it doesn't do anymore for >=portage-2.1.4_rc4. Does this ebuild work around the "0 problem" or is it not working with stable portage? Is it a candidate for stabling, or would you rather wait some more days? No, it doesn't work around the O problem, so I don't think it will work with stable portage. any news here? Marijn, which version of Portage is this issue fixed in? Do you have a Portage bug for reference? I feel a little lost how to handle this thing right now. The issue is fixed as of >=portage-2.1.4_rc4. I didn't file any bug for it. Zmedico probably remembers though. The right version for Portage is stabilised already. For bug 209052 a newer chicken version is needed stable, so we can go with that? Or do you want to handle chicken here and swig there? chicken 3.0.0 is not going to be stable. We'll have to wait some more. :) I'm happy to have chicken-3.1.0 stabled now. (In reply to comment #10) > I'm happy to have chicken-3.1.0 stabled now. > hmm sorry, It seems to have been stabled in the meanwhile. So I guess we can move forward to the glsa part. GLSA 200805-11 |