Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 142559 - x11-misc/x11vnc includes vulnerable libvncserver? (CVE-2006-2450)
Summary: x11-misc/x11vnc includes vulnerable libvncserver? (CVE-2006-2450)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B1 [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2006-08-02 08:54 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2008-03-06 09:42 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-02 08:54:39 UTC
See bug #136916 for further details.
Comment 1 Sven Wegener gentoo-dev 2006-08-02 10:36:40 UTC
looking at the source >=x11-misc/x11vnc-0.8.1 are fixed, 0.8.1 is no longer in the tree, 0.8.2 can be marked stable
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-02 23:49:40 UTC
Arches please test and mark stable.
Comment 3 Tobias Scherbaum (RETIRED) gentoo-dev 2006-08-03 11:31:30 UTC
ppc stable
Comment 4 Paul Varner (RETIRED) gentoo-dev 2006-08-03 11:43:49 UTC
x86 stable.
Comment 5 René Nussbaumer (RETIRED) gentoo-dev 2006-08-04 05:45:01 UTC
Stable on hppa. Sorry for the delay.
Comment 6 Michael Weyershäuser 2006-08-04 10:09:52 UTC
emerges & works fine on amd64...

emerge --info
Portage 2.1-r1 (default-linux/amd64/2006.0, gcc-3.4.6, glibc-2.3.6-r4, 2.6.17-suspend2-r3-Dudebox-Edition x86_64)
=================================================================
System uname: 2.6.17-suspend2-r3-Dudebox-Edition x86_64 AMD Athlon(tm) 64 Processor 3200+
Gentoo Base System version 1.6.15
ccache version 2.3 [enabled]
app-admin/eselect-compiler: [Not Present]
dev-lang/python:     2.4.3-r1
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.3
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.59-r7
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.13-r3
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS="amd64"
AUTOCLEAN="yes"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=k8 -O2 -pipe -msse3"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf /etc/revdep-rebuild /etc/terminfo"
CXXFLAGS="-march=k8 -O2 -pipe -msse3"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig ccache collision-protect distlocks metadata-transfer multilib-strict parallel-fetch sandbox sfperms strict test userfetch userpriv usersandbox"
GENTOO_MIRRORS="ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp:///ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/"
LINGUAS="de"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude='/distfiles' --exclude='/local' --exclude='/packages'"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://server/gentoo-portage"
USE="amd64 X alsa arts avi berkdb bitmap-fonts cli crypt cups dlloader dri eds emboss encode foomaticdb fortran gif gnome gpm gstreamer gtk gtk2 imlib ipv6 isdnlog jpeg kde kdeenablefinal lzw lzw-tiff mp3 mpeg ncurses nls nptl opengl pam pcre pdflib perl png pppd python qt qt3 qt4 quicktime readline reflection sdl session spell spl ssl tcpd tiff truetype-fonts type1-fonts unicode usb userlocales xorg xpm xv zlib elibc_glibc input_devices_keyboard input_devices_mouse input_devices_evdev kernel_linux linguas_de userland_GNU video_cards_dummy"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LDFLAGS, MAKEOPTS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 7 Thomas Cort (RETIRED) gentoo-dev 2006-08-04 10:15:22 UTC
amd64 stable.
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-05 00:19:02 UTC
This one is ready for GLSA.
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-07 12:08:21 UTC
GLSA 200608-12

sh dont forget to mark stable to benifit from the GLSA.
Comment 10 Peter Volkov (RETIRED) gentoo-dev 2008-03-06 09:42:00 UTC
Does not affect current (2008.0) release. Removing release.