Gentoo Archives: gentoo-user

From: Grant Edwards <grant.b.edwards@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] I don't understand version numbers in Gentoo security advisories
Date: Thu, 03 Mar 2016 21:01:03
Message-Id: nba8lb$bec$1@ger.gmane.org
1 I'm sure I'm just being stupid, but I don't understand the lists of
2 affected and unaffected version numbers in Gentoo security advisories.
3
4 For example:
5
6 Package dev-libs/openssl on all architectures
7 Affected versions < 1.0.2f
8
9 Unaffected versions >= 1.0.2f, revision >= 1.0.1r, revision >= 1.0.1s,
10 revision >= 1.0.1t, revision >= 0.9.8z_p8,
11 revision >= 0.9.8z_p9, revision >= 0.9.8z_p10,
12 revision >= 0.9.8z_p11, revision >= 0.9.8z_p12,
13 revision >= 0.9.8z_p13, revision >= 0.9.8z_p14,
14 revision >= 0.9.8z_p15
15
16 If it's true that versions >= 0.9.8z_p8 are unaffected,
17 why is there a need to list that versions >= 0.9.8z_p[9-15] are
18 unaffected? Are <> relationships betwen version numbers within the
19 0.9.8z_pNNN seriels not transitive?
20
21 --
22 Grant Edwards grant.b.edwards Yow! MMM-MM!! So THIS is
23 at BIO-NEBULATION!
24 gmail.com

Replies