Gentoo Archives: gentoo-dev

From: Stefan Cornelius <dercorny@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed
Date: Mon, 29 May 2006 16:37:34
Message-Id: 1148920740.2185.11.camel@localhost
1 Hi Gang,
2
3 net-www/awstats is masked because it has open security issues (including
4 remote code execution), see bug #130487 for details. Version 6.6 was
5 made to fix it, but unfortunately this version is not working at all
6 (see bug #134296), so we are trapped between unusable and vulnerable
7 versions.
8
9 Jakub made a patch for version 6.5 to fix this vulnerabilities, but that
10 very patch still needs to be incorporated into an ebuild and commited as
11 revbump.
12
13 So, if anyone volunteers to step up and revbump 6.5 with patch (or fix
14 6.6 so that it's usable), please don't hesitate. It would be also cool
15 to have a new maintainer for this one, since ka0ttic seems to be
16 missing.
17
18
19 Thanks in advance,
20
21 Stefan 'DerCorny' Cornelius
22
23 --
24 gentoo-dev@g.o mailing list

Replies