Summary: | <app-text/texlive-core-2015-r1: Insecure temporary file vulnerability (CVE-2012-2120) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | aballier, spamfilter-1, tex, toralf |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
=app-text/texlive-2015
=dev-texlive/texlive-basic-2015
=dev-texlive/texlive-bibtexextra-2015
=dev-texlive/texlive-context-2015
=dev-texlive/texlive-fontsextra-2015
=dev-texlive/texlive-fontsrecommended-2015
=dev-texlive/texlive-fontutils-2015
=dev-texlive/texlive-formatsextra-2015
=dev-texlive/texlive-games-2015
=dev-texlive/texlive-genericextra-2015
=dev-texlive/texlive-genericrecommended-2015
=dev-texlive/texlive-humanities-2015
=dev-texlive/texlive-langafrican-2015
=dev-texlive/texlive-langarabic-2015
=dev-texlive/texlive-langchinese-2015
=dev-texlive/texlive-langcjk-2015
=dev-texlive/texlive-langcyrillic-2015
=dev-texlive/texlive-langczechslovak-2015-r1
=dev-texlive/texlive-langenglish-2015
=dev-texlive/texlive-langeuropean-2015
=dev-texlive/texlive-langfrench-2015
=dev-texlive/texlive-langgerman-2015
=dev-texlive/texlive-langgreek-2015
=dev-texlive/texlive-langindic-2015
=dev-texlive/texlive-langitalian-2015
=dev-texlive/texlive-langjapanese-2015
=dev-texlive/texlive-langkorean-2015
=dev-texlive/texlive-langother-2015
=dev-texlive/texlive-langpolish-2015
=dev-texlive/texlive-langportuguese-2015
=dev-texlive/texlive-langspanish-2015
=dev-texlive/texlive-latexextra-2015-r1
=dev-texlive/texlive-latexrecommended-2015-r1
=dev-texlive/texlive-latex-2015
=dev-texlive/texlive-luatex-2015
=dev-texlive/texlive-mathextra-2015
=dev-texlive/texlive-metapost-2015
=dev-texlive/texlive-music-2015
=dev-texlive/texlive-omega-2015
=dev-texlive/texlive-pictures-2015-r2
=dev-texlive/texlive-plainextra-2015
=dev-texlive/texlive-pstricks-2015
=dev-texlive/texlive-publishers-2015
=dev-texlive/texlive-science-2015
=dev-texlive/texlive-xetex-2015
=dev-libs/kpathsea-6.2.1_p20150521-r2
=dev-libs/ptexenc-1.3.3_p20150521
=app-text/ps2pkm-1.7_p20150521
=app-text/dvipsk-5.995_p20150521
=dev-tex/bibtexu-3.71_p20150521
=app-text/ttf2pk2-2.0_p20150521
=app-text/texlive-core-2015-r1
=app-text/teckit-2.5.6
=dev-tex/pgf-3.0.1
=app-text/xdvik-22.87.03
=dev-tex/tex4ht-20090611_p1038-r4
=dev-tex/cjk-latex-4.8.4
|
Runtime testing required: | --- |
Bug Depends on: | 604400 | ||
Bug Blocks: | 555220, 571330, 594314, 630544, 644388 |
Description
GLSAMaker/CVETool Bot
![]() Maintainer's does the stable version: 2012-r1 contains the fixes? If so please advise so we can get the bug out. If it does not have the fix please advise what version is ready to go stable that has the security fixes. Reference: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668779 it doesnt seem fixed even in tl 2014; might be worth poking upstream (bug is really minor i think) I contacted the author of latex2man. commit fcf4ed88aa06db4717d827e5586b876fc10f739a Author: Alexis Ballier <aballier@gentoo.org> Date: Mon Dec 5 15:34:47 2016 +0100 app-text/texlive-core: apply debian patch to fix unsafe /tmp usage. Bug #432144. app-text/texlive-core-2015-r1 so, now we should get the whole texlive 2015 stable @ Maintainer(s): Thank you for the rev bump! Can you please provide a list of all packages which need to be stabilized? Stabilization will happen in this bug. (sorry for the noise, I'm trying to see if the stable-bot can help having a proper list) okey, so here is a complete list of texlive 2015 packages; ccing arches, let's see what the bot finds out Toralf: the kpathsea version in this list might break building some of its reverse dependencies; could you please check if a stable tree with this package list stable is fine in that regard ? (In reply to Alexis Ballier from comment #8) I just setup a new stable image (but with gcc-5.40) and the package list will be started with the packages names given in that bug report An automated check of this bug failed - repoman reported dependency errors (486 lines truncated):
> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: alpha(default/linux/alpha/13.0) ['>=app-text/xdvik-22.87', '>=dev-tex/tex4ht-20090611_p1038-r3']
> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: alpha(default/linux/alpha/13.0/desktop) ['>=app-text/xdvik-22.87', '>=dev-tex/tex4ht-20090611_p1038-r3']
> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: alpha(default/linux/alpha/13.0/desktop/gnome) ['>=app-text/xdvik-22.87', '>=dev-tex/tex4ht-20090611_p1038-r3']
> dependency.bad dev-texlive/texlive-pictures/texlive-pictures-2015-r2.ebuild: DEPEND: hppa(default/linux/hppa/13.0) ['>=dev-tex/pgf-3.0.1']
> dependency.bad dev-texlive/texlive-pictures/texlive-pictures-2015-r2.ebuild: RDEPEND: hppa(default/linux/hppa/13.0) ['>=dev-tex/pgf-3.0.1']
> dependency.bad app-text/texlive-core/texlive-core-2015-r1.ebuild: DEPEND: alpha(default/linux/alpha/13.0) ['>=app-text/teckit-2.5.3']
> dependency.bad app-text/texlive-core/texlive-core-2015-r1.ebuild: RDEPEND: alpha(default/linux/alpha/13.0) ['>=app-text/teckit-2.5.3']
> dependency.bad app-text/texlive-core/texlive-core-2015-r1.ebuild: DEPEND: alpha(default/linux/alpha/13.0/desktop) ['>=app-text/teckit-2.5.3']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Dropping ia64 & sparc for now, we'll need to readd later because of bug #604400 An automated check of this bug failed - repoman reported dependency errors:
> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: hppa(default/linux/hppa/13.0) ['>=dev-tex/cjk-latex-4.8.4']
readding ia64 & sparc: https://qa-reports.gentoo.org/output/gentoo-ci/3c3d3614d/output.html#app-text/texlive https://qa-reports.gentoo.org/output/gentoo-ci/3c3d3614d/output.html#app-text/texlive-core broken deps are already included in that list so you can just proceed here and remove the mask for bug #604400 An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
amd64 stable x86 stable An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Stable on alpha. An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
ppc stable An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
*** Bug 602426 has been marked as a duplicate of this bug. *** Stable for HPPA. An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
ppc64 stable. An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
arm stable. An automated check of this bug failed - repoman reported dependency errors (318 lines truncated):
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
Dropping ia64 for the moment which has some problems with Ruby. Maintainers/ATs can decide to start re-keywording once new texlive has been stabilized and problems for ia64 are resolved. An automated check of this bug failed - repoman reported dependency errors (102 lines truncated):
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
Dropping sparc for the same reason. (In reply to Thomas Deutschmann from comment #29) > Dropping ia64 for the moment which has some problems with Ruby. (In reply to Thomas Deutschmann from comment #31) > Dropping sparc for the same reason. Are sparc & ia64 profiles going to be demoted to dev ? If no, how do you expect cleanup of vulnerable versions to happen ? (In reply to Alexis Ballier from comment #32) > (In reply to Thomas Deutschmann from comment #29) > > Dropping ia64 for the moment which has some problems with Ruby. > > (In reply to Thomas Deutschmann from comment #31) > > Dropping sparc for the same reason. > > Are sparc & ia64 profiles going to be demoted to dev ? > > If no, how do you expect cleanup of vulnerable versions to happen ? Council decided in December 2016 to allow security project to drop security coverage for sparc/ia64 if these arches can't keep up. After talking with both ATs about texlive (well, only Agostino) it became clear that texlive won't go stable on ia64/sparc anytime soon. So it is time to drop the packages for these architectures. Do whatever works for you: Either drop ia64/sparc keyword, even for already stable texlive package which will be needed for cleanup or apply package.masks to indicate a security problem. (In reply to Thomas Deutschmann from comment #33) > Do whatever works for you: Either drop ia64/sparc keyword, even for already > stable texlive package which will be needed for cleanup or apply > package.masks to indicate a security problem. Nothing like this will work. If the profiles remain marked as "stable" this will break all the revdeps needing anything latex, creating fatal repoman warnings for those packages; there are quite a few, even for those arches I think. You should ask the so-called council to rethink a bit this decision: Either mark those profiles as dev or forget about security cleanup. (In reply to Alexis Ballier from comment #34) > (In reply to Thomas Deutschmann from comment #33) > > Do whatever works for you: Either drop ia64/sparc keyword, even for already > > stable texlive package which will be needed for cleanup or apply > > package.masks to indicate a security problem. > > Nothing like this will work. If the profiles remain marked as "stable" this > will break all the revdeps needing anything latex, creating fatal repoman > warnings for those packages; there are quite a few, even for those arches I > think. > > You should ask the so-called council to rethink a bit this decision: Either > mark those profiles as dev or forget about security cleanup. The latter, cleanup isn't really security critical, so bugs stay open a bit longer, but it doesn't impact user security and can be filtered on by whiteboard keywords. ia64/sparc not being security supported means GLSAs can go out and other processing can be done as usual without waiting for the arches. (In reply to Kristian Fiskerstrand from comment #35) > (In reply to Alexis Ballier from comment #34) > > (In reply to Thomas Deutschmann from comment #33) > > > Do whatever works for you: Either drop ia64/sparc keyword, even for already > > > stable texlive package which will be needed for cleanup or apply > > > package.masks to indicate a security problem. > > > > Nothing like this will work. If the profiles remain marked as "stable" this > > will break all the revdeps needing anything latex, creating fatal repoman > > warnings for those packages; there are quite a few, even for those arches I > > think. > > > > You should ask the so-called council to rethink a bit this decision: Either > > mark those profiles as dev or forget about security cleanup. > > The latter, cleanup isn't really security critical, so bugs stay open a bit > longer, but it doesn't impact user security and can be filtered on by > whiteboard keywords. ia64/sparc not being security supported means GLSAs can > go out and other processing can be done as usual without waiting for the > arches. To elaborate, in case it isn't clear from the above. The mask for the package is done by the GLSA in this case, so no external mask necessary (or wanted) Maintainer(s), please drop the vulnerable version(s). Ping: No updates since 05/17. Security Team Padawan ChrisADR |