Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 89501

Summary: dev-perl/Convert-UUlib New version fix security issue
Product: Gentoo Security Reporter: Sune Kloppenborg Jeppesen <jaervosz>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: net-mail, perl
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
Whiteboard: B2? [glsa] jaervosz
Package list:
Runtime testing required: ---

Description Sune Kloppenborg Jeppesen gentoo-dev 2005-04-18 03:16:48 UTC
Snippet from Changelog:

1.05 Fri Feb 25 22:50:27 CET 2005
        - fix a (likely exploitable) segfault problem, (tracked down
          and/or reported by Mark Martinec and Robert Lewis).
Comment 1 Michael Cummings (RETIRED) gentoo-dev 2005-04-18 10:25:41 UTC
1.051 in the tree and ready for arch's to test.
Comment 2 Sune Kloppenborg Jeppesen gentoo-dev 2005-04-18 10:29:42 UTC
Arches please test and mark stable.
Comment 3 Jan Brinkmann (RETIRED) gentoo-dev 2005-04-18 10:34:32 UTC
any hints for testing?
Comment 4 Gustavo Zacarias (RETIRED) gentoo-dev 2005-04-18 10:38:23 UTC
FEATURES="maketest" emerge ... :)
Most perl stuff has autotests, specially when the ebuild has SRC_TEST="do".
Comment 5 Jan Brinkmann (RETIRED) gentoo-dev 2005-04-18 11:10:33 UTC
stable on amd64
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-04-18 11:32:38 UTC
Stable on ppc.
Comment 7 Michael Cummings (RETIRED) gentoo-dev 2005-04-18 12:36:24 UTC
SRC_TEST="do" is enabled by default - I can provide additional tests if you have some functionality in mind you want to test :)

Unless rep's from x86 or sparc mind, I can test and bump for these platforms.
Comment 8 Michael Cummings (RETIRED) gentoo-dev 2005-04-18 13:46:38 UTC
Stable for x86 and sparc.
Comment 9 Bryan Ƙstergaard (RETIRED) gentoo-dev 2005-04-19 11:14:40 UTC
Stable on alpha.
Comment 10 Sune Kloppenborg Jeppesen gentoo-dev 2005-04-19 12:30:32 UTC
tigger/taviso could you look into this and perhaps provide a bit more detail for a GLSA?
Comment 11 Michael Cummings (RETIRED) gentoo-dev 2005-04-19 13:25:58 UTC
Shouldn't we get the amavis && amavisd-new maintainers on this bug? They should bump their ebuilds to specifically reflect the new version
Comment 12 Sune Kloppenborg Jeppesen gentoo-dev 2005-04-19 13:39:24 UTC
net-mail please bump dependencies.
Comment 13 Markus Rothe (RETIRED) gentoo-dev 2005-04-19 23:24:13 UTC
stable on ppc64
Comment 14 Andrej Kacian (RETIRED) gentoo-dev 2005-04-20 00:18:25 UTC
Both amavis and amavisd-new bumped to use >=dev-perl/Convert-UUlib-1.051
Comment 15 Sune Kloppenborg Jeppesen gentoo-dev 2005-04-21 01:27:45 UTC
Upstream contacted by taviso.
Comment 16 Sune Kloppenborg Jeppesen gentoo-dev 2005-04-26 22:52:21 UTC
GLSA 200504-26