Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 215699

Summary: net-misc/ltsp-4 Multiple vulnerabilities
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: enhancement CC: dberkholz, fauli, maintainer-needed
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2? [removed glsa]
Package list:
Runtime testing required: ---
Bug Depends on: 177580    
Bug Blocks:    

Description Robert Buchholz (RETIRED) gentoo-dev 2008-04-01 13:30:28 UTC
net-misc/ltsp ships ancient copies of a whole linux system, including Kernel, zlib, libpng and X11.

CVE-2008-1293 was recently assigned, but might only affect LTSP 5. I did not even try to reproduce it with LTSP 4.

We have to mask this package until bug 177580 is taken care of.
Comment 1 Christian Faulhammer (RETIRED) gentoo-dev 2008-04-01 18:48:56 UTC
Have done it...proxy maintenance was a total failure.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-04-01 19:21:48 UTC
maskglsa'ing it
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-04-03 22:31:08 UTC
Christian, you could also mask only <net-misc/ltsp-5 to cause less interference with the ltsp-5 development in the overlay.
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2008-04-04 06:06:22 UTC
(In reply to comment #3)
> Christian, you could also mask only <net-misc/ltsp-5 to cause less interference
> with the ltsp-5 development in the overlay.

 Done.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-05-09 14:34:25 UTC
maskglsa 200805-07
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2009-07-27 09:08:31 UTC
Removals:
...
net-misc/ltsp                           2009-07-21 13:12:57     flameeyes