1 |
Daniel Iliev wrote: |
2 |
> |
3 |
> Hi, |
4 |
> |
5 |
> Since I'm not familiar with Gentoo's practice in dealing with |
6 |
> security problems I got curious about the following case. |
7 |
> Yesterday a Secunia advisory [1] about pidgin was brought to my |
8 |
> attention. The solution offered by the up-streams is upgrading to |
9 |
> version 2.5.6, while the latest version in portage is "~2.5.5-r1". |
10 |
> |
11 |
> As I see it, there are three possibilities: |
12 |
> 1) even older, the version in Gentoo is not affected, because the |
13 |
> maintainers had taken care of it (too optimistic?) |
14 |
> 2) Gentoo installations are still vulnerable to the bugs described in |
15 |
> the advisory and nobody knows about it (quite disturbing) |
16 |
> 3) Gentoo maintainers are working on it, but still not ready |
17 |
> |
18 |
> Which one is it? |
19 |
> |
20 |
> |
21 |
> [1] [SA35194] http://secunia.com/advisories/35194/ |
22 |
> |
23 |
> |
24 |
|
25 |
https://bugs.gentoo.org/show_bug.cgi?id=270811 |