Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 578218

Summary: GLSA 201603-15: too high version number given for affected packages
Product: Gentoo Security Reporter: Rolf Eike Beer <eike>
Component: GLSA ErrorsAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Rolf Eike Beer archtester 2016-03-25 14:01:30 UTC
<unaffected range="ge">1.0.2g-r2</unaffected>
      <vulnerable range="lt">1.0.2g-r2</vulnerable>

This is not correct, versions 1.0.2g and 1.0.2g-r1 are not affected, too. This now annoys everyone who did a quick fix with a (local) overlay. I now run a local overlay that has ssl2 entirely disabled.

Reproducible: Always
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2016-03-25 16:24:58 UTC
Both ebuilds for -r0 and -r1 expose technical defects. Suggesting users to use those is not a good option.