1 |
Daniel Iliev wrote: |
2 |
> On Sat, 23 May 2009 09:23:27 -0400 |
3 |
> Saphirus Sage <saphirus497@×××××.com> wrote: |
4 |
> |
5 |
> |
6 |
>> Daniel Iliev wrote: |
7 |
>> |
8 |
>>> Hi, |
9 |
>>> |
10 |
>>> Since I'm not familiar with Gentoo's practice in dealing with |
11 |
>>> security problems I got curious about the following case. |
12 |
>>> Yesterday a Secunia advisory [1] about pidgin was brought to my |
13 |
>>> attention. The solution offered by the up-streams is upgrading to |
14 |
>>> version 2.5.6, while the latest version in portage is "~2.5.5-r1". |
15 |
>>> |
16 |
>>> As I see it, there are three possibilities: |
17 |
>>> 1) even older, the version in Gentoo is not affected, because the |
18 |
>>> maintainers had taken care of it (too optimistic?) |
19 |
>>> 2) Gentoo installations are still vulnerable to the bugs |
20 |
>>> described in the advisory and nobody knows about it (quite |
21 |
>>> disturbing) 3) Gentoo maintainers are working on it, but still not |
22 |
>>> ready |
23 |
>>> |
24 |
>>> Which one is it? |
25 |
>>> |
26 |
>>> |
27 |
>>> [1] [SA35194] http://secunia.com/advisories/35194/ |
28 |
>>> |
29 |
>>> |
30 |
>>> |
31 |
>>> |
32 |
>> It's in portage, sync your tree and check again. I just installed |
33 |
>> Pidgin 2.5.6 last night. |
34 |
>> |
35 |
>> |
36 |
> |
37 |
> I guess the mirror I'm using is not up-to-date and they will get a |
38 |
> report about it, |
39 |
> |
40 |
> Thanks! |
41 |
> |
42 |
> |
43 |
I sync from rsync://rsync21.us.gentoo.org/gentoo-portage primarily due |
44 |
to the fact that it's an unlimited-sync server. |