Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 273107 - <net-misc/tigervnc-1.0.0-r4 bundles an internal copy of jpeg and zlib
Summary: <net-misc/tigervnc-1.0.0-r4 bundles an internal copy of jpeg and zlib
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Raúl Porcel (RETIRED)
URL:
Whiteboard: B2 [stable]
Keywords: STABLEREQ
Depends on:
Blocks: bundled-libs
  Show dependency tree
 
Reported: 2009-06-07 20:30 UTC by Diego Elio Pettenò (RETIRED)
Modified: 2010-03-14 10:58 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Diego Elio Pettenò (RETIRED) gentoo-dev 2009-06-07 20:30:29 UTC
Check ${S}/common/jpeg.
Comment 1 Samuli Suominen (RETIRED) gentoo-dev 2010-03-02 16:40:14 UTC
This is caused by poorly written ebuild, the build-system supports using the system copies

  --with-included-zlib    use libz which is distributed with VNC
  --with-system-jpeg      use libjpeg which is distributed with the O/S

--without-included-zlib and --with-system-jpeg to econf

The jpeg is at least vulnerable to GLSA-200606-11

Please fix the ebuild or lastrite the package
Comment 2 Raúl Porcel (RETIRED) gentoo-dev 2010-03-02 19:15:33 UTC
Arches, please stabilize =net-misc/tigervnc-1.0.0-r3, only change is use system's zlib+jpeg.

Thanks Samuli for the fix
Comment 3 Raúl Porcel (RETIRED) gentoo-dev 2010-03-02 19:48:29 UTC
gah, nvm
Comment 4 Samuli Suominen (RETIRED) gentoo-dev 2010-03-02 20:03:55 UTC
... The fix goes to ./configure in common/ directory
Comment 5 Raúl Porcel (RETIRED) gentoo-dev 2010-03-02 20:34:18 UTC
Please stabilize =net-misc/tigervnc-1.0.0-r4
Comment 6 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-03-03 10:29:43 UTC
x86 stable
Comment 7 Tiago Cunha (RETIRED) gentoo-dev 2010-03-04 01:41:23 UTC
sparc stable
Comment 8 Raúl Porcel (RETIRED) gentoo-dev 2010-03-04 19:31:51 UTC
alpha/arm/ia64/sh stable
Comment 9 Brent Baude (RETIRED) gentoo-dev 2010-03-08 16:55:50 UTC
ppc64 done
Comment 10 Joe Jezak (RETIRED) gentoo-dev 2010-03-09 19:27:33 UTC
Marked ppc stable.
Comment 11 Jeroen Roovers (RETIRED) gentoo-dev 2010-03-12 17:36:14 UTC
Stable for HPPA.
Comment 12 Markus Meier gentoo-dev 2010-03-14 10:58:17 UTC
amd64 stable, all arches done.