Summary: | www-misc/htdig: Unspecified Input Validation Hole Permits Cross-Site Scripting Attacks | ||||||
---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Jean-François Brunette (RETIRED) <formula7> | ||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | minor | CC: | jaervosz, web-apps | ||||
Priority: | High | ||||||
Version: | unspecified | ||||||
Hardware: | All | ||||||
OS: | All | ||||||
URL: | http://securitytracker.com/alerts/2005/Feb/1013078.html | ||||||
Whiteboard: | B4 [glsa] | ||||||
Package list: | Runtime testing required: | --- | |||||
Attachments: |
|
Description
Jean-François Brunette (RETIRED)
![]() Created attachment 50309 [details, diff]
htdig-3.2.0b6-unescaped_output.patch
Patch from RedHat
web-apps: please apply and bump *** Bug 79691 has been marked as a duplicate of this bug. *** I've backported the patch to 3.1.6; qtest.cc doesn't exist in this release, so I've only patched htsearch.cc. 3.1.6-r7 is stable on x86. amd64, ppc, and sparc, please mark stable. stable on amd64 Stable on ppc. htdig-3.1.6-r4.ebuild has SLOT="0" and htdig-3.1.6-r7.ebuild does not. This is causing both version to want to be installed simultaneously. Shouldn't the new ebuild set the slot as well? > htdig-3.1.6-r4.ebuild has SLOT="0" and htdig-3.1.6-r7.ebuild does not. This is causing both version to want to be installed simultaneously. Shouldn't the new ebuild set the slot as well?
Karl, no and actually it's not even possible to set SLOT in ebuilds that inherit webapp.eclass. SLOT is handled by webapps.eclass which r4 doesn't use (it uses the older deprecated webapp-apache).
Stable on SPARC. Security please vote on GLSA. I vote for a GLSA on this one. dito GLSA 200502-16 |