Gentoo Archives: gentoo-dev

From: Christian Heim <phreak@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] PHP security status
Date: Sun, 15 Jul 2007 13:46:16
Message-Id: 200707151543.10815.phreak@gentoo.org
In Reply to: [gentoo-dev] PHP security status by "Hanno Böck"
1 On Sunday 15 July 2007 15:02:45 Hanno Böck wrote:
2 > Hi,
3 >
4 > At the moment, we have a quite problematic situation with the php ebuilds.
5 > Due to various people doing research on php-issues, there has been a vast
6 > number of security issues in the last months (mopb and others).
7 >
8 > We still have 5.2.2 in the tree. A user, christian hoffmann, is maintaining
9 > some ebuilds in the php-experimental-overlay. They've, from what I know,
10 > fixed nearly all issues, beside one openbasedir-bypass, where we fail to
11 > find a patch (CVE-2007-3378).
12 >
13 > Now, chtekk has been very rarely available lately. chtekk, could you raise
14 > your voice and tell us if you'll be back soon or if we could merge stuff
15 > without you in the meantime.
16
17 As you might know from his away status (either from IRC or the devaway¹ page),
18 Luca is currently doing his mandatory military service for his country till
19 November iirc.
20
21 > Christian is doing a quite well job in the overlay. I'd prefer if we could
22 > merge his work into the main tree. I could do that, although I'd prefer to
23 > get some review from other devs. php is a hell to maintain I think.
24
25 1:http://www.gentoo.org/proj/en/devrel/roll-call/devaway.xml?select=chtekk#chtekk
26
27 Regards,
28
29 Christian
30
31 --
32 Christian Heim <phreak at gentoo.org>
33 GPG key ID: 9A9F68E6
34 Fingerprint: AEC4 87B8 32B8 4922 B3A9 DF79 CAE3 556F 9A9F 68E6

Attachments

File name MIME type
signature.asc application/pgp-signature