Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 244424 - net-libs/libgadu-1.8.2 released
Summary: net-libs/libgadu-1.8.2 released
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All All
: High enhancement (vote)
Assignee: Gentoo Net-im project
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: CVE-2008-4776
  Show dependency tree
 
Reported: 2008-10-26 08:22 UTC by Jakub Zawadzki
Modified: 2009-02-04 17:28 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
libgadu-1.8.2 ebuild (libgadu-1.8.2.ebuild,792 bytes, text/plain)
2008-12-08 19:10 UTC, PM
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Jakub Zawadzki 2008-10-26 08:22:30 UTC
libgadu 1.8.2 was released 2 days ago.
release notes: http://toxygen.net/libgadu/releases/1.8.2.html (polish only)
Comment 1 Mike Auty (RETIRED) gentoo-dev 2008-10-26 11:29:42 UTC
Jakub, please familiarize yourself with the severity scale (http://bugs.gentoo.org/page.cgi?id=fields.html#bug_severity).  You've filed an enhancement, not a major bug.

Also, please either leave a bug to be triaged by the bug-wranglers, or if you really have to assign it directly to the relevant people.  Assigning it to the wranglers and then manually CCing the maintainers is guaranteed to waste someone's time.
Comment 2 PM 2008-12-08 19:10:10 UTC
Created attachment 174665 [details]
libgadu-1.8.2 ebuild

Nobody seems to care, so here's the ebuild (just bumped the file name).

Just put it in the tree, please.
Comment 3 Marcin Dzierzkowski 2008-12-17 10:35:58 UTC
libgadu 1.8.2 has security fixes, earlier versions have several vulnerabilities; for example in checking buddies description status length - it may cause segmentation fault, so update is good idea.
-MD
Comment 4 adriancz 2009-02-04 13:17:10 UTC
I think that security bugs should have severity set to critical and priority to P1. I can't understand why such trivial fix (change version number in ebuild) hasn't been fixed yet.
Comment 5 Piotr Szymaniak 2009-02-04 15:26:52 UTC
@adriancz
This comment should go to bug #244888. (;
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2009-02-04 17:28:04 UTC
*libgadu-1.8.2 (04 Feb 2009)

  04 Feb 2009; Robert Buchholz <rbu@gentoo.org>
  -libgadu-1.7.0_pre20050719.ebuild, -libgadu-1.7.0.ebuild,
  -libgadu-1.8.0.ebuild, +libgadu-1.8.2.ebuild:
  Version bump (bug #244424), fixing a buffer overread vulnerability (bug
  #244888)