Gentoo Archives: gentoo-user

From: Justin <justin@×××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] security
Date: Sat, 23 May 2009 13:31:44
Message-Id: 4A17FAAF.5040308@j-schmitz.net
In Reply to: [gentoo-user] security by Daniel Iliev
1 Daniel Iliev wrote:
2 >
3 > Hi,
4 >
5 > Since I'm not familiar with Gentoo's practice in dealing with
6 > security problems I got curious about the following case.
7 > Yesterday a Secunia advisory [1] about pidgin was brought to my
8 > attention. The solution offered by the up-streams is upgrading to
9 > version 2.5.6, while the latest version in portage is "~2.5.5-r1".
10 >
11 > As I see it, there are three possibilities:
12 > 1) even older, the version in Gentoo is not affected, because the
13 > maintainers had taken care of it (too optimistic?)
14 > 2) Gentoo installations are still vulnerable to the bugs described in
15 > the advisory and nobody knows about it (quite disturbing)
16 > 3) Gentoo maintainers are working on it, but still not ready
17 >
18 > Which one is it?
19 >
20 >
21 > [1] [SA35194] http://secunia.com/advisories/35194/
22 >
23 >
24
25 https://bugs.gentoo.org/show_bug.cgi?id=270811

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] [solved] security Daniel Iliev <daniel.iliev@×××××.com>