Gentoo Archives: gentoo-user

From: Saphirus Sage <saphirus497@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] security
Date: Sat, 23 May 2009 13:37:18
Message-Id: 4A17FC01.5070505@gmail.com
In Reply to: Re: [gentoo-user] security by Daniel Iliev
1 Daniel Iliev wrote:
2 > On Sat, 23 May 2009 09:23:27 -0400
3 > Saphirus Sage <saphirus497@×××××.com> wrote:
4 >
5 >
6 >> Daniel Iliev wrote:
7 >>
8 >>> Hi,
9 >>>
10 >>> Since I'm not familiar with Gentoo's practice in dealing with
11 >>> security problems I got curious about the following case.
12 >>> Yesterday a Secunia advisory [1] about pidgin was brought to my
13 >>> attention. The solution offered by the up-streams is upgrading to
14 >>> version 2.5.6, while the latest version in portage is "~2.5.5-r1".
15 >>>
16 >>> As I see it, there are three possibilities:
17 >>> 1) even older, the version in Gentoo is not affected, because the
18 >>> maintainers had taken care of it (too optimistic?)
19 >>> 2) Gentoo installations are still vulnerable to the bugs
20 >>> described in the advisory and nobody knows about it (quite
21 >>> disturbing) 3) Gentoo maintainers are working on it, but still not
22 >>> ready
23 >>>
24 >>> Which one is it?
25 >>>
26 >>>
27 >>> [1] [SA35194] http://secunia.com/advisories/35194/
28 >>>
29 >>>
30 >>>
31 >>>
32 >> It's in portage, sync your tree and check again. I just installed
33 >> Pidgin 2.5.6 last night.
34 >>
35 >>
36 >
37 > I guess the mirror I'm using is not up-to-date and they will get a
38 > report about it,
39 >
40 > Thanks!
41 >
42 >
43 I sync from rsync://rsync21.us.gentoo.org/gentoo-portage primarily due
44 to the fact that it's an unlimited-sync server.

Replies

Subject Author
Re: [gentoo-user] security Daniel Iliev <daniel.iliev@×××××.com>