Gentoo Archives: gentoo-dev

From: Thierry Carrez <koon@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Last rites for glukalka, junkie, napshare, gv4l, dyndnsupdate
Date: Sun, 12 Jun 2005 14:52:45
Message-Id: 42AC4C4A.90204@gentoo.org
1 The following packages will be removed from Portage in 48 hours, unless
2 someone steps up to fix the corresponding security bugs - and takeover
3 upstream when it's dead :)
4
5 app-emulation/glukalka (bug 70666)
6 No upstream and vulnerable to multiple tempfile vulns and race
7 conditions, this package has been masked since 2004-11-26, with noone
8 missing it.
9
10 net-ftp/junkie (bug 74696)
11 No upstream and vulnerable to remote execution of code, this package has
12 been masked since 2004-12-30, no complaints received.
13
14 net-p2p/napshare (bug 74703)
15 Vulnerable to remote execution of code, the new version does not compile
16 correctly and no maintainer stepped up. This package has been masked
17 since 2005-01-07, apparently noone is missing it.
18
19 media-video/gv4l (bug 82631)
20 No upstream answer, and vulnerable to various local problems, this
21 package has been masked since 2005-03-18, nobody asked for it.
22
23 net-misc/dyndnsupdate (bug 84659)
24 No upstream and vulnerable to remote execution of code, this package has
25 been masked since 2005-03-21, with everyone switching to more secure
26 alternatives.
27
28 --
29 Thierry Carrez (Koon)
30 Operational Manager, Gentoo Linux Security

Attachments

File name MIME type
signature.asc application/pgp-signature