Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 207353 - www-apps/phpBB 3.X security status
Summary: www-apps/phpBB 3.X security status
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Default Configs (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.phpbb.com/about/features/
Whiteboard:
Keywords:
Depends on:
Blocks: 211166
  Show dependency tree
 
Reported: 2008-01-25 08:13 UTC by Gunnar Wrobel (RETIRED)
Modified: 2010-03-28 00:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gunnar Wrobel (RETIRED) gentoo-dev 2008-01-25 08:13:08 UTC
According to their own words phpBB-3.0.0 now has significantly improved with respect to security.

It has been hard masked in our tree for quite a while now and I added phpBB-3.0.0 today.

Given that it is a frequently used webapp I wanted to ask whether we should consider removing the hard mask. We should probably wait a while to see if their will be any sec bugs for 3.0.0 in the coming weeks but I think it can't hurt to document the status of the package as we do it for wordpress and xoops.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-01-25 08:24:11 UTC
If security fixes are applied in a timely manner to the ebuild I see no problem in unmasking. But as you note it would probably be wise to wait a few weeks.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-03-02 11:14:46 UTC
Is phpBB 3.0.0 affected by bug 210948?
Comment 3 Benedikt Böhm (RETIRED) gentoo-dev 2008-03-07 12:36:12 UTC
phpBB-3.0.0 seems good so far, i've unmasked it now .. phpBB-2 still masked, but i have added an ebuild for 2.0.23 wrt bug 210948
Comment 4 Matthew Dirks 2008-03-26 21:41:28 UTC
phpBB-3.0.0 is still arch-masked. Any ETA on when it might be stable (at the least for x86)?
Comment 5 Jean-Noël Rivasseau (RETIRED) gentoo-dev 2008-09-02 08:09:02 UTC
Can we ask for a STABLEREQ for this package now? I believe it has been long enough ~x86 without problems, it should be marked stable
Comment 6 Gunnar Wrobel (RETIRED) gentoo-dev 2008-09-07 17:43:08 UTC
Removed phpBB-2* and removed the mask. Closing bug.

@Jean-Noël Rivasseau:

I'm not too much in favor of unmasking stuff in www-apps at the moment simply because web-apps is a herd with low man power. Stable apps require swifter action to security issues which I feel cannot be guaranteed at the moment.