Gentoo Archives: gentoo-server

From: mRyOuNg <mryoung@×××××××××.net>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] what happend to GLSA ?
Date: Tue, 08 Jan 2008 18:24:54
Message-Id: 4783BFEA.4000605@soundbomb.net
In Reply to: [gentoo-server] what happend to GLSA ? by Tomasz Lutelmowski
1 Tomasz Lutelmowski wrote:
2 > The GLSA is not updating since 2007-12-25...
3 >
4 > xxx etc # glsa-check -l | tail
5 > [A] means this GLSA was already applied,
6 > [U] means the system is not affected and
7 > [N] indicates that the system might be affected.
8 >
9 > 200712-16 [U] Exiv2: Integer overflow ( media-gfx/exiv2 )
10 > 200712-17 [U] exiftags: Multiple vulnerabilities ( media-gfx/exiftags )
11 > 200712-18 [U] Multi-Threaded DAAP Daemon: Multiple vulnerabilities ( media-
12 > sound/mt-daapd )
13 > 200712-19 [U] Syslog-ng: Denial of Service ( app-admin/syslog-ng )
14 > 200712-20 [U] ClamAV: Multiple vulnerabilities ( app-antivirus/clamav )
15 > 200712-21 [U] Mozilla Firefox, SeaMonkey: Multiple vulnerabilities ( www-
16 > client/seamonkey www-client/mozilla-firefox-bin www-client/mozilla-
17 > firefox ... )
18 > 200712-22 [U] Opera: Multiple vulnerabilities ( www-client/opera )
19 > 200712-23 [U] Wireshark: Multiple vulnerabilities ( net-analyzer/wireshark )
20 > 200712-24 [U] AMD64 x86 emulation GTK+ library: User-assisted execution of
21 > arbitrary code ( app-emulation/emul-linux-x86-gtklibs )
22 > 200712-25 [U] OpenOffice.org: User-assisted arbitrary code execution ( app-
23 > office/openoffice app-office/openoffice-bin dev-db/hsqldb )
24 >
25 > Is it temporary issue or Gentoo got new way of tracking vulnerabilities ?
26 >
27 > Regards,
28 > TOmek
29 >
30
31 Hi there ...
32
33 Hmm, if i remember well, the last number has nothing todo with the day ...
34 200712-25 means ... 25th Security Advisory during December 2007
35
36 Maybe i'm wrong, but one sure thing is that the last number as nothing
37 to do with the day ...
38 for example
39 # glsa-check -d 200712-17 | grep "Announced"
40 Announced on: December 29, 2007
41
42 cya!
43 --
44 . mRyOuNg :: [ SoundBomb . Syn[Rj] ] .
45 mail: mryoung@×××××××××.net
46 web : mryoung.soundbomb.net

Attachments

File name MIME type
signature.asc application/pgp-signature