Summary: | dev-lang/wml < 2.0.11-r3 Insecure temp file usage (CVE-2008-0665, CVE-2008-0666) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Pierre-Yves Rofes (RETIRED) <py> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | graaff |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://secunia.com/advisories/28856/ | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Pierre-Yves Rofes (RETIRED)
![]() here's the patch, courtesy of Debian: http://people.debian.org/~nion/nmu-diff/wml-2.0.11-3_2.0.11-3.1.patch Hans, please bump. Hans, please bump. Apologies for the delay: vacations and real-life have been getting in the way. I hope to be able to get to it this weekend at the latest. Hans, that sounds fine. Next time just post an update the first time so we know what to do:-) The attached patch seems to break wml... I'll see what I can do over the weekend, but this does change the level of work needed. I've just added wml-2.0.11-r3 to the tree with a reworked version of the Debian patch. I'd like to give it a few days as unstable to catch any remaining bugs. No bug reports so far and seems to work fine on my own sites. I think we can mark this stable now. Arches, please test and mark stable: =dev-lang/wml-2.0.11-r3 Target keywords : "amd64 ia64 ppc release s390 sparc x86" ppc stable x86 stable ia64/sparc stable amd64 stable Fixed in release snapshot. Ready for vote. I vote YES. yes too, request filed. GLSA 200803-23 |