Summary: | <x11-wm/xmonad-contrib-0.11.2 : Remote command injection (CVE-2013-1436) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | haskell |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2013/07/26/5 | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() Pushed as:
>*xmonad-contrib-0.11.2 (27 Jul 2013)
>
> 27 Jul 2013; Sergei Trofimovich <slyfox@gentoo.org>
> +xmonad-contrib-0.11.2.ebuild:
> Version bump (fixes CVE-2013-1436).
Will require stabilising
x86, amd64
at least the following packages:
=x11-wm/xmonad-contrib-0.11.2
=dev-haskell/x11-1.6.1.1
=dev-haskell/data-default-0.5.3
=dev-haskell/data-default-class-0.0.1
=dev-haskell/data-default-instances-base-0.0.1
=dev-haskell/data-default-instances-containers-0.0.1
=dev-haskell/data-default-instances-dlist-0.0.1
=dev-haskell/data-default-instances-old-locale-0.0.1
=dev-haskell/dlist-0.5-r1
=x11-wm/xmonad-0.11-r1
All, except today's xmonad-contrib-0.11.2 sit in the tree for some months.
(In reply to Sergei Trofimovich from comment #1) > Pushed as: > > >*xmonad-contrib-0.11.2 (27 Jul 2013) > > > > 27 Jul 2013; Sergei Trofimovich <slyfox@gentoo.org> > > +xmonad-contrib-0.11.2.ebuild: > > Version bump (fixes CVE-2013-1436). > > Will require stabilising > > x86, amd64 > > at least the following packages: > > =x11-wm/xmonad-contrib-0.11.2 > =dev-haskell/x11-1.6.1.1 > =dev-haskell/data-default-0.5.3 > =dev-haskell/data-default-class-0.0.1 > =dev-haskell/data-default-instances-base-0.0.1 > =dev-haskell/data-default-instances-containers-0.0.1 > =dev-haskell/data-default-instances-dlist-0.0.1 > =dev-haskell/data-default-instances-old-locale-0.0.1 > =dev-haskell/dlist-0.5-r1 > =x11-wm/xmonad-0.11-r1 > > All, except today's xmonad-contrib-0.11.2 sit in the tree for some months. this list is fine from a repoman side. All right then. Arches, please stabilize the packages from comment #1, target arches: amd64 x86. Thanks! amd64 stable x86 stable GLSA vote: yes GLSA vote: yes GLSA request filed This issue was resolved and addressed in GLSA 201405-28 at http://security.gentoo.org/glsa/glsa-201405-28.xml by GLSA coordinator Sergey Popov (pinkbyte). |