Gentoo Archives: gentoo-dev

From: Stefan Cornelius <dercorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed
Date: Tue, 30 May 2006 14:22:24
Message-Id: 1148998935.24317.11.camel@localhost
In Reply to: [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed by Stefan Cornelius
1 CHTEKK does this one, thanks.
2
3
4 > Hi Gang,
5 >
6 > net-www/awstats is masked because it has open security issues (including
7 > remote code execution), see bug #130487 for details. Version 6.6 was
8 > made to fix it, but unfortunately this version is not working at all
9 > (see bug #134296), so we are trapped between unusable and vulnerable
10 > versions.
11 >
12 > Jakub made a patch for version 6.5 to fix this vulnerabilities, but that
13 > very patch still needs to be incorporated into an ebuild and commited as
14 > revbump.
15 >
16 > So, if anyone volunteers to step up and revbump 6.5 with patch (or fix
17 > 6.6 so that it's usable), please don't hesitate. It would be also cool
18 > to have a new maintainer for this one, since ka0ttic seems to be
19 > missing.
20 >
21 >
22 > Thanks in advance,
23 >
24 > Stefan 'DerCorny' Cornelius
25 >
26
27 --
28 gentoo-dev@g.o mailing list