Summary: | <sys-devel/bison-3.5.4: Multiple vulnerabilities (CVE-2020-14150) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | base-system, fedora.dm0 |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://lists.gnu.org/archive/html/info-gnu/2020-04/msg00000.html | ||
See Also: |
https://bugs.gentoo.org/show_bug.cgi?id=739018 https://bugs.gentoo.org/show_bug.cgi?id=730488 https://bugs.gentoo.org/show_bug.cgi?id=737026 |
||
Whiteboard: | A3 [noglsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 739018 |
Description
Sam James
2020-04-17 18:19:26 UTC
@maintainer(s), please advise if ready for stabilisation, or call yourself. Given that these crashes are unlikely, if you are not yet comfortable with stabilisation, there is no problem. ping Why not go straight for 3.6.4? (In reply to Andreas Sturmlechner from comment #3) > Why not go straight for 3.6.4? Yes, that would be great. hppa stable sparc stable x86 stable Restarting stabilization with newer version due to bug 704894. Sanity check failed:
> sys-devel/bison-3.7.1
> bdepend amd64 stable profile default/linux/amd64/17.0 (79 total)
> >=sys-devel/gettext-0.21
> bdepend amd64 dev profile default/linux/amd64/17.0/no-multilib/prefix/kernel-3.2+ (35 total)
> >=sys-devel/gettext-0.21
All sanity-check issues have been resolved *** Bug 733710 has been marked as a duplicate of this bug. *** x86 stable s390 done s390 done ppc done amd64 done arm64 done sparc done ppc64 done arm done Unable to check for sanity:
> no match for package: sys-devel/bison-3.7.1
hppa stable (In reply to Sergei Trofimovich from comment #22) > hppa stable Nope, wrong package name. Returning. All sanity-check issues have been resolved hppa stable Unable to check for sanity:
> no match for package: sys-devel/bison-3.7.1-r1
Please cleanup, if possible Unable to check for sanity:
> no match for package: sys-devel/bison-3.7.1-r1
All vulnerable versions gone Thank you! All done. |