Summary: | www-apps/viewcvs: tar export abuse (CAN-2004-0915) | ||||||
---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Thierry Carrez (RETIRED) <koon> | ||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | normal | CC: | rl03, stuart | ||||
Priority: | High | ||||||
Version: | unspecified | ||||||
Hardware: | All | ||||||
OS: | All | ||||||
URL: | http://www.debian.org/security/2004/dsa-605 | ||||||
Whiteboard: | B4 [glsablocked] koon | ||||||
Package list: | Runtime testing required: | --- | |||||
Bug Depends on: | 73772 | ||||||
Bug Blocks: | |||||||
Attachments: |
|
Description
Thierry Carrez (RETIRED)
2004-11-25 06:27:21 UTC
Created attachment 44712 [details, diff]
patch.CAN-2004-0915.viewcvs.0.9.2
Patch for 0.9.x viewcvs
Renat this is a restricted bug, please prepare a fixed ebuild and have it ready when a disclosure date is agreed with vendor-sec. Ccing Stuart as rl03 seems inactive Can we commit this patch into portage, or do we have to wait until vendor-sec declassify the bug? Thanks, Stu We still have to wait before pushing any of this in a public repository. You can attach the ebuild (or a tarball with the ebuild and files) to this bug, so that we can push them for early stable testing to selected devs. This is public now. Stuart please commit the patch. viewcvs-0.9.2_p20041207.ebuild has been added, and marked stable on x86. Needs marking stable on ppc. Please note: I've done minimal testing on this package. Best regards, Stu ppc, please mark viewcvs-0.9.2_p20041207 stable. stable on ppc Security please vote on GLSA on this one. I would vote for a GLSA Debian published a DSA already btw. Yes, GLSA needed. I'll handle this together with bug 73772 GLSA 200412-26 |