Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 519400 - =net-misc/stunnel-5.03 rapid stable request
Summary: =net-misc/stunnel-5.03 rapid stable request
Status: RESOLVED OBSOLETE
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Keywording and Stabilization (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Anthony Basile
URL: https://www.stunnel.org/sdf_ChangeLog...
Whiteboard:
Keywords: STABLEREQ
Depends on: 523534
Blocks:
  Show dependency tree
 
Reported: 2014-08-08 12:29 UTC by Anthony Basile
Modified: 2014-11-17 12:18 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Anthony Basile gentoo-dev 2014-08-08 12:29:13 UTC
Upstream has marked this update as urgent.

TARGET = alpha amd64 arm hppa ia64 ppc ppc64 sparc x86 

Reproducible: Always
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2014-08-08 14:31:23 UTC
The upstream ChangeLog doesn't list any reason for an urgent stabilisation, barring the OpenSSL security bug that only affects their Windows binaries.

Stable for HPPA.
Comment 2 Agostino Sarubbo gentoo-dev 2014-08-08 15:28:35 UTC
If we don't use a bundled version of openssl, then there is no update for us.
Comment 3 Anthony Basile gentoo-dev 2014-08-09 12:40:40 UTC
(In reply to Jeroen Roovers from comment #1)
> The upstream ChangeLog doesn't list any reason for an urgent stabilisation,
> barring the OpenSSL security bug that only affects their Windows binaries.
> 
> Stable for HPPA.

Correct, but in src/ctx.c they relaxed a precompiler condition which looks like it might be for enhanced security:

-#if defined(USE_WIN32) || OPENSSL_VERSION_NUMBER>=0x0090700fL
+#if OPENSSL_VERSION_NUMBER>=0x0090700fL
     SSL_CTX_set_default_passwd_cb(section->ctx, password_cb);
 #endif

I can't make sense if this is related to any of the stuff in the openssl security advisory: https://www.openssl.org/news/secadv_20140806.txt.  So I erred on the side of caution.
Comment 4 Anthony Basile gentoo-dev 2014-08-09 12:41:23 UTC
(In reply to Agostino Sarubbo from comment #2)
> If we don't use a bundled version of openssl, then there is no update for us.

That's not what's going on here.  See my previous comment.
Comment 5 Anthony Basile gentoo-dev 2014-08-12 22:21:24 UTC
stable on ppc, ppc64 and arm.
Comment 6 Anthony Basile gentoo-dev 2014-09-22 11:10:06 UTC
stable amd64/x86
Comment 7 Anthony Basile gentoo-dev 2014-11-17 12:18:04 UTC
@remaining arch teams: please start work on bug #528004