Gentoo Archives: gentoo-dev

From: Samuli Suominen <ssuominen@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Lastrite: media-sound/teamspeak2-{client,server}-bin (security: copy of libpng 1.0.9)
Date: Tue, 21 Jul 2009 14:00:49
Message-Id: 4A65CA28.5030605@gentoo.org
In Reply to: Re: [gentoo-dev] Lastrite: media-sound/teamspeak2-{client,server}-bin (security: copy of libpng 1.0.9) by Nicolas Peyron
1 Nicolas Peyron wrote:
2 > On Tue, 21 Jul 2009 16:20:47 +0300, Samuli Suominen <ssuominen@g.o>
3 > wrote:
4 >> Samuli Suominen wrote:
5 >>> # Samuli Suominen <ssuominen@g.o> (21 Jul 2009)
6 >>> # Security problems. Internal copies of vulnerable libraries,
7 >>> # such as libpng. See, http://bugs.gentoo.org/show_bug.cgi?id=251492
8 >>> # Masked for removal.
9 >>> media-sound/teamspeak2-server-bin
10 >>> media-sound/teamspeak2-client-bin
11 >>>
12 >> Also vulnerable copy of libspeex...
13 >
14 > Why server and client both, the server doesn't have a copy of libspeex and
15 > doesn't bundle libpng or zlib.
16 >
17
18 How about vulnerable copy of openssl, in /opt/teamspeak2-server/server_linux
19
20 CVEs; GLSAs. And don't ask me to check which ones, there's many.