Summary: | gnome-extra/yelp <2.22.1-r2 gtk_message_dialog_format_secondary_markup() Format string vulnerability (CVE-2008-3533) | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> | ||||||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||||||
Status: | RESOLVED FIXED | ||||||||||
Severity: | normal | CC: | gnome | ||||||||
Priority: | High | ||||||||||
Version: | unspecified | ||||||||||
Hardware: | All | ||||||||||
OS: | Linux | ||||||||||
URL: | https://bugs.launchpad.net/bugs/254860 | ||||||||||
Whiteboard: | A2/B2 [glsa] | ||||||||||
Package list: | Runtime testing required: | --- | |||||||||
Attachments: |
|
Description
Robert Buchholz (RETIRED)
![]() Created attachment 162428 [details, diff]
Proposed patch
Created attachment 162430 [details]
2.20.0 bump ebuild for most arches
Created attachment 162431 [details]
2.22.1 bump ebuild for amd64
Okay, here's a patch, and 2 ebuilds that apply it. Most arches have 2.20.0 stable, but 2.22 is in the process of going stable (and amd64 has it stable). All arches that are going stable with 2.22 should test both (except amd64 which only needs to test 2.22.1-r2). Fortunately, the same patch applies to both. Thanks for patch and ebuild. Arch Security Liaisons, please test the attached ebuild and report it stable on this bug. Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sh sparc x86" CC'ing current Liaisons: alpha : yoswink, armin76 amd64 : keytoaster, tester hppa : jer ppc : dertobi123 ppc64 : corsair sparc : fmccor x86 : maekke, armin76 yelp-2.22.1-r2 looks good on amd64/x86. looks good on ppc64 Looks okay on alpha/ia64/sparc HPPA is OK. yelp-2.22.1-r2 okay for ppc Public via $URL. Please commit with the stable keywords gathered in this bug. Committed. GLSA 200809-01 |