Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 82460

Summary: net-misc/bidwatcher: CAN-2005-0158
Product: Gentoo Security Reporter: Matthias Geerdsen (RETIRED) <vorlon>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: mholzer
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://sourceforge.net/project/shownotes.php?release_id=305937
Whiteboard: B2 [glsa] jaervosz
Package list:
Runtime testing required: ---

Description Matthias Geerdsen (RETIRED) gentoo-dev 2005-02-18 07:25:18 UTC
Release Name: 1.3.17
* Fix potential security bug in versions <= 1.3.16 (CAN-2005-0158: thanks to Ulf.Harnhammar.9485@student.uu.se)

___

http://secunia.com/advisories/14324/

___

This package is lacking metadata.xml/maintainer.
mholzer, you have bumped it the last times. If you want to step up as maintainer, then add a metadata.xml file and bump the package pls.

If no one is willing to take maintainership, this package will probably be  masked/removed.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-02-18 07:30:51 UTC
*** Bug 81577 has been marked as a duplicate of this bug. ***
Comment 2 solar (RETIRED) gentoo-dev 2005-02-18 08:36:04 UTC
Adding the following to profiles/package.mask

+# <solar@gentoo> (18 Feb 2005)
+# All version below 1.3.17 have exploitable format string problems. The 
+# bidwatcher package lacks a maintainer and metadata and will most 
+# likely be punted from the tree. Bug #82460 (CAN-2005-0158)
+<=net-misc/bidwatcher-1.3.16

Comment 3 Martin Holzer (RETIRED) gentoo-dev 2005-02-28 13:47:42 UTC
in cvs
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-03-01 00:44:04 UTC
Back to main scope, GLSA status
Martin: care to add yourself to metadata.xml ?
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-02 22:43:19 UTC
New version is not masked. Martin please see comment #4 and add yourself to metadata.xml
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-03 13:59:40 UTC
GLSA 200503-06

Martin please remember to add yourself to the metadata.xml