Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 105695 - x11-libs/qt includes vulnerable zlib
Summary: x11-libs/qt includes vulnerable zlib
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.trolltech.com/developer/ch...
Whiteboard: B2? [glsa] jaervosz
Keywords:
Depends on:
Blocks: 105719
  Show dependency tree
 
Reported: 2005-09-12 08:31 UTC by Sune Kloppenborg Jeppesen
Modified: 2006-03-23 19:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen gentoo-dev 2005-09-12 08:31:11 UTC
It appears as if qt is using it's own version of zlib if the zlib USE flag is  
not set.  
  
From 3.3.5 Changelog: 
 
Added security patches for zlib: CAN-2005-1849, CAN-2005-2096
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-09-12 09:01:52 UTC
Hm. Let's say USE=-zlib is quite uncommon and rate this B2.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-09-17 05:39:26 UTC
KDE team: your position on this, please.
Comment 3 Caleb Tennis (RETIRED) gentoo-dev 2005-09-18 07:21:25 UTC
FYI: 3.3.5 is in portage now, as unstable.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-09-18 09:35:32 UTC
Thanks Caleb. Is it a candidate for stable right now ?
Comment 5 Gregorio Guidi (RETIRED) gentoo-dev 2005-09-19 03:03:42 UTC
(In reply to comment #4) 
> Thanks Caleb. Is it a candidate for stable right now ? 
 
I think not, see bug 106402. 
 
I suggest to commit qt-3.3.4-r8, the only difference to -r7 being that it 
forces "-system-zlib" as a compilation option. 
qt-3.3.4-r7 was ready to go stable, so qt-3.3.4-r8 could go stable right now. 
 
Comment 6 Sune Kloppenborg Jeppesen gentoo-dev 2005-09-19 03:40:39 UTC
Back to ebuild status, waiting for a suitable ebuild to mark stable.  
Comment 7 Caleb Tennis (RETIRED) gentoo-dev 2005-09-19 05:15:37 UTC
#5 works for me. 
Comment 8 Sune Kloppenborg Jeppesen gentoo-dev 2005-09-19 05:58:57 UTC
Yeah it does for me as well if -r8 gets committed. 
Comment 9 Caleb Tennis (RETIRED) gentoo-dev 2005-09-19 07:06:46 UTC
-r8 is committed, but not yet stable on any arches.  I don't see why it can't 
go stable right away, but I'd like one more opinion on the matter (greg?). 
Comment 10 Gregorio Guidi (RETIRED) gentoo-dev 2005-09-19 08:32:00 UTC
I agree that it can go stable right now. Actually I was going to propose -r7 
for stable just before this bug showed up. 
 
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-09-19 08:59:03 UTC
OK, let's go then: archs please test and mark 3.3.4-r8 stable
Target KEYWORDS="alpha amd64 hppa ia64 mips ppc ppc64 ~ppc-macos sparc x86"
Comment 12 Marcus D. Hanwell (RETIRED) gentoo-dev 2005-09-19 10:39:28 UTC
This version also introduces a dep on ~dev-db/qt-unixODBC-3.3.4 which isn't 
currently stable on amd64 and has an open security bug against it (bug 105719) 
- advise on this please. 
Comment 13 Caleb Tennis (RETIRED) gentoo-dev 2005-09-19 19:04:33 UTC
I've committed a patch to the qt-unixodbc ebuild that should fix the RUNPATH problem.
Comment 14 Markus Rothe (RETIRED) gentoo-dev 2005-09-19 21:15:09 UTC
stable on ppc64 
Comment 15 Gustavo Zacarias (RETIRED) gentoo-dev 2005-09-20 07:25:06 UTC
sparc stable (with qt-unixODBC-3.3.4-r1).
Comment 16 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-09-20 10:27:13 UTC
Stable on hppa, ppc
Comment 17 Marcus D. Hanwell (RETIRED) gentoo-dev 2005-09-20 11:42:42 UTC
Looks good - stable on amd64. 
Comment 18 Fernando J. Pereda (RETIRED) gentoo-dev 2005-09-21 02:34:48 UTC
Looks ok on alpha.
Comment 19 Mark Loeser (RETIRED) gentoo-dev 2005-09-21 18:43:01 UTC
Stable on x86
Comment 20 Thierry Carrez (RETIRED) gentoo-dev 2005-09-22 01:59:19 UTC
Common GLSA with the qt-unixodbc thing ?
Comment 21 Sune Kloppenborg Jeppesen gentoo-dev 2005-09-22 04:02:54 UTC
Let's do a common GLSA with qt. 
Comment 22 Sune Kloppenborg Jeppesen gentoo-dev 2005-09-22 04:06:29 UTC
with qt-unixodbc of course :-) 
Comment 23 Sune Kloppenborg Jeppesen gentoo-dev 2005-09-26 13:56:00 UTC
GLSA 200509-18  
  
ia64 and mips don't forget to mark stable to benifit from the GLSA. 
Comment 24 Hardave Riar (RETIRED) gentoo-dev 2005-09-28 18:37:05 UTC
Stable on mips.