Summary: | media-gfx/blender <2.48-r3: search path vulnerability (CVE-2008-4863) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Stefan Behte (RETIRED) <craig> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | graphics+disabled, lu_zero |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503632 | ||
Whiteboard: | B4 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Stefan Behte (RETIRED)
![]() ![]() Debian patch: http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=10;filename=pythonpath.diff;att=1;bug=503632 I assume that all versions in the tree are affected? (2.48a seems to have the same issue...) As we have media-gfx/blender-2.43 stable, we would have to backport the fix to this version (which should be pretty easy). *blender-2.48a-r3 (03 Nov 2008) *blender-2.48a-r2 (03 Nov 2008) *blender-2.43-r3 (03 Nov 2008) 03 Nov 2008; Markus Meier <maekke@gentoo.org> +files/blender-2.43-CVE-2008-4863.patch, +files/blender-2.48a-CVE-2008-4863.patch, +blender-2.43-r3.ebuild, +blender-2.48a-r2.ebuild, +blender-2.48a-r3.ebuild: security bumps for 2.43 (for stable) and 2.48a, bug #245310 @lu_zero: do you have any objections to remove all all ebuilds, except for blender-2.43-r3 (when it's stable), and >=2.48a-r2 ? Arches, please test and mark stable: =media-gfx/blender-2.43-r3 Target keywords : "ppc ppc64 x86" ppc64 stable x86 stable ppc stable time for glsa decision, voting yes. YES too, request filed. GLSA 201001-07, thanks everyone. |