Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 564592 - =net-fs/davfs2-1.5.2 stable request
Summary: =net-fs/davfs2-1.5.2 stable request
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Network Filesystems
URL:
Whiteboard:
Keywords: STABLEREQ
Depends on:
Blocks: CVE-2013-4362
  Show dependency tree
 
Reported: 2015-11-01 01:26 UTC by Christian Tietz
Modified: 2015-12-07 11:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christian Tietz 2015-11-01 01:26:11 UTC
Long enough in the tree. Probably also fixes #485232.

Reproducible: Always
Comment 1 Christian Tietz 2015-11-01 14:30:49 UTC
Just realized it has not yet been 30 days. May bad. Please wait a couple more days with this.
Comment 2 Göktürk Yüksek archtester gentoo-dev 2015-11-01 17:08:11 UTC
There is an open security bug for this and the most stable version in the tree is vulnerable. See bug 485232.
Comment 3 Pacho Ramos gentoo-dev 2015-11-04 14:48:18 UTC

*** This bug has been marked as a duplicate of bug 485232 ***
Comment 4 Pacho Ramos gentoo-dev 2015-11-04 14:50:24 UTC
(In reply to Gokturk Yuksek from comment #2)
> There is an open security bug for this and the most stable version in the
> tree is vulnerable. See bug 485232.

Is or not is vulnerable? (reading from the security bug looks like this was ok finally... in that case, it doesn't matter what bug is used for stabilizing this, but, please, remember to set STABLEREQ in the bug keywords and also to use "depends on" and "blocks" bug fields if needed ;)

Thanks
Comment 5 Göktürk Yüksek archtester gentoo-dev 2015-11-06 00:23:13 UTC
(In reply to Pacho Ramos from comment #4)
> (In reply to Gokturk Yuksek from comment #2)
> > There is an open security bug for this and the most stable version in the
> > tree is vulnerable. See bug 485232.
> 
> Is or not is vulnerable? (reading from the security bug looks like this was
> ok finally... in that case, it doesn't matter what bug is used for
> stabilizing this, but, please, remember to set STABLEREQ in the bug keywords
> and also to use "depends on" and "blocks" bug fields if needed ;)
> 
> Thanks

Pacho, the security bug text is confusing. I also assumed it when I read the comment "Fixed in versions davfs2/1.4.7-3, davfs2/1.4.6-1.1+deb7u1". There is no 1.4.7 in the tree. According to the changelog[1], this is fixed in 1.5.0, not 1.4.7. There is a proposed patch for 1.4.7[2]. Nobody actually revbumped the packages to include these patches. As such, 1.5.2 is the only unaffected version in the tree which is why I wanted to push for it's stabilization.

[1] https://savannah.nongnu.org/forum/forum.php?forum_id=7952
[2] https://savannah.nongnu.org/bugs/?40034
Comment 6 Göktürk Yüksek archtester gentoo-dev 2015-11-06 00:24:05 UTC
I meant there is no 1.4.7-3 in the tree.
Comment 7 Ian Delaney (RETIRED) gentoo-dev 2015-11-29 01:55:56 UTC
on behalf of prompt by user Gokturk Yuksek
Comment 8 Agostino Sarubbo gentoo-dev 2015-11-30 09:17:18 UTC
amd64 stable
Comment 9 Agostino Sarubbo gentoo-dev 2015-12-03 13:29:03 UTC
x86 stable
Comment 10 Agostino Sarubbo gentoo-dev 2015-12-07 11:42:03 UTC
ppc stable. Closing.