Gentoo Archives: gentoo-user

From: Volker Armin Hemmann <volkerarmin@××××××××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] security
Date: Sat, 23 May 2009 15:15:37
Message-Id: 200905231715.31069.volkerarmin@googlemail.com
In Reply to: [gentoo-user] security by Daniel Iliev
1 On Samstag 23 Mai 2009, Daniel Iliev wrote:
2 > Hi,
3 >
4 > Since I'm not familiar with Gentoo's practice in dealing with
5 > security problems I got curious about the following case.
6 > Yesterday a Secunia advisory [1] about pidgin was brought to my
7 > attention. The solution offered by the up-streams is upgrading to
8 > version 2.5.6, while the latest version in portage is "~2.5.5-r1".
9 >
10 > As I see it, there are three possibilities:
11 > 1) even older, the version in Gentoo is not affected, because the
12 > maintainers had taken care of it (too optimistic?)
13 > 2) Gentoo installations are still vulnerable to the bugs described in
14 > the advisory and nobody knows about it (quite disturbing)
15 > 3) Gentoo maintainers are working on it, but still not ready
16 >
17 > Which one is it?
18 >
19 >
20 > [1] [SA35194] http://secunia.com/advisories/35194/
21
22 subscribe to gentoo-announce
23 read changelogs
24 don't forget that it takes a while until all mirrors have that change.