Gentoo Archives: gentoo-dev

From: Thierry Carrez <koon@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Dropping phpgroupware from the Portage tree
Date: Mon, 21 Nov 2005 08:44:59
Message-Id: 43818864.6020007@gentoo.org
In Reply to: [gentoo-dev] Dropping phpgroupware from the Portage tree by Stuart Herbert
1 Stuart Herbert wrote:
2
3 > I've just masked the package 'www-apps/phpgroupware', and will be
4 > dropping it from the tree soon. There are a number of issues with the
5 > project, including:
6 >
7 > * Outstanding security bugs
8 > * Upstream homepage no longer available
9 > * No real releases in over a year
10
11 FYI, I just received the following from Dave Hall
12 <phpgw@×××××××××××××××××.org> :
13
14 > Hi all,
15 >
16 > You are encouraged to update to the latest version of phpGroupWare -
17 > 0.9.16.009. The release contains several major bug fixes as well as
18 > some important security fixes.
19 >
20 > You can grab the new version from -
21 > http://sourceforge.net/project/showfiles.php?group_id=7305
22 >
23 > Or update from cvs
24 > $ cd /path/to/phpgroupware
25 > $ export CVS_RSH=ssh
26 > $ cvs update -dP
27 >
28 > Changelog is as follows:
29 >
30 > Fixes for the following security issues:
31 > * phpSysInfo
32 > - XSS CVE-2005-0870
33 > - arbitrary file inclusion CVE-2005-3347
34 > - anti XSS measure CVE-2005-3348
35 > * FUDForum
36 > - arbitary code execution SA16627
37 >
38 > Major bug fixes:
39 > - LDAP account returns only phpGroupWare accounts
40 > - accounts list pages and sorts properly
41 > - Next account id is properly generated
42 > - First group shows properly in ACL manager
43 > - Calendar footer now shows again
44 > - Calendar alarms can be set, editted and viewed
45 > - Fix apps to work with anti XSS code from 007/8
46 > - News Admin
47 > - Sitemgr
48 >
49 > Additional languages and translated phrases
50 >
51 > We hope to have our website back up and running in the 24hours, so for
52 > the inconvenience this may be causing people.
53 >
54 > Cheers
55 > Dave
56
57 So it looks like it's still maintained and the homepage problem is
58 temporary...
59
60 --
61 Koon
62 --
63 gentoo-dev@g.o mailing list