Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#20475 - [libcdaudio] Security patches missing and alpha source is used
Attached to Project:
Arch Linux
Opened by kujub (kujub) - Saturday, 14 August 2010, 18:36 GMT
Last edited by Jan de Groot (JGC) - Tuesday, 17 August 2010, 10:23 GMT
Opened by kujub (kujub) - Saturday, 14 August 2010, 18:36 GMT
Last edited by Jan de Groot (JGC) - Tuesday, 17 August 2010, 10:23 GMT
|
DetailsDescription:
Security issues: * User-assisted execution of arbitrary code http://www.gentoo.org/security/en/glsa/glsa-200903-31.xml http://bugs.gentoo.org/show_bug.cgi?id=245649 * CDDB response overflow http://www.gentoo.org/security/en/glsa/glsa-200504-07.xml http://bugs.gentoo.org/show_bug.cgi?id=84936 Attached patches used in Gentoo libcdaudio-0.99.12-r1.ebuild Moreover the PKGBUILD is *not* using source version 0.99.12, but 0.99.12p2 which is an [quote] Alpha version. Unworthy to be distributed. [/quote] http://sourceforge.net/project/shownotes.php?release_id=349530 Additional info: * package version(s) 0.99.12-4 |
This task depends upon
Closed by Jan de Groot (JGC)
Tuesday, 17 August 2010, 10:23 GMT
Reason for closing: Fixed
Additional comments about closing: 0.99.12-5.
Tuesday, 17 August 2010, 10:23 GMT
Reason for closing: Fixed
Additional comments about closing: 0.99.12-5.
Comment by Gerardo Exequiel Pozzi (djgera) -
Saturday, 14 August 2010, 22:52 GMT
- Field changed: Status (Unconfirmed → Assigned)
- Task assigned to Andrea Scarpino (BaSh), Dan Griffiths (Ghost1227), Giovanni Scafora (giovanni), Hugo Doria (hdoria)
Also assigned to orphan team, since Hugo are not around here.
libcdaudio-0.99.12-bug245649....