Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 525506 (CVE-2014-6540) - <app-emulation/virtualbox-{,-bin}-4.3.18: multiple vulnerabilities (CVE-2014-6540)
Summary: <app-emulation/virtualbox-{,-bin}-4.3.18: multiple vulnerabilities (CVE-2014-...
Status: RESOLVED FIXED
Alias: CVE-2014-6540
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.oracle.com/technetwork/top...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks: 500064
  Show dependency tree
 
Reported: 2014-10-15 16:03 UTC by Agostino Sarubbo
Modified: 2015-03-18 18:05 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-10-15 16:03:09 UTC
See ${URL} for details.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-10-15 16:46:00 UTC
Arches please test and mark stable the following set of packages:

=app-emulation/virtualbox-4.3.16
=app-emulation/virtualbox-additions-4.3.16
=app-emulation/virtualbox-bin-4.3.16
=app-emulation/virtualbox-extpack-oracle-4.3.16
=app-emulation/virtualbox-guest-additions-4.3.16
=app-emulation/virtualbox-modules-4.3.16
=dev-util/kbuild-0.1.9998_pre20131130
=x11-drivers/xf86-video-virtualbox-4.3.16

Target keywords are:
amd64 x86
Comment 2 Agostino Sarubbo gentoo-dev 2014-10-16 07:24:04 UTC
emerge: there are no ebuilds to satisfy "=app-emulation/virtualbox-extpack-oracle-4.3.16".
Comment 3 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-10-16 15:41:12 UTC
Sorry, cut'n'paste error :-(

Here's the correct list:

=app-emulation/virtualbox-4.3.16
=app-emulation/virtualbox-additions-4.3.16
=app-emulation/virtualbox-bin-4.3.16.95972
=app-emulation/virtualbox-extpack-oracle-4.3.16.95972
=app-emulation/virtualbox-guest-additions-4.3.16
=app-emulation/virtualbox-modules-4.3.16
=dev-util/kbuild-0.1.9998_pre20131130
=x11-drivers/xf86-video-virtualbox-4.3.16
Comment 4 Agostino Sarubbo gentoo-dev 2014-10-19 17:59:46 UTC
I have the known failure on hardened.

@ Poly-c: if works for you, go ahead and stabilize for amd64 and x86.
Comment 5 Agostino Sarubbo gentoo-dev 2014-12-06 17:07:43 UTC
FTR:

  dependency.bad                9                                                                                                                                                   
   app-emulation/virtualbox/virtualbox-4.3.16.ebuild: DEPEND: amd64(default/linux/amd64/13.0) ['net-libs/gsoap[-gnutls]']
Comment 6 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-12-22 13:15:01 UTC
I've stabilized virtualbox-4.3.18 packages (although 4.2.20 might have been the better choice but it's too late now).

Dunno if we need a GLSA for this.
Comment 7 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-12-22 13:17:07 UTC
(In reply to Lars Wendler (Polynomial-C) from comment #6)
> I've stabilized virtualbox-4.3.18 packages (although 4.2.20 might have been
> the better choice but it's too late now).
> 
> Dunno if we need a GLSA for this.

4.3.20 might have been the better choice, not 4.2.20
Comment 8 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-03-18 17:47:42 UTC
GLSA Vote: No
Comment 9 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-03-18 18:05:38 UTC
GLSA vote: no.

Closing as [noglsa]