1 |
On Sat, 23 May 2009 09:23:27 -0400 |
2 |
Saphirus Sage <saphirus497@×××××.com> wrote: |
3 |
|
4 |
> Daniel Iliev wrote: |
5 |
> > Hi, |
6 |
> > |
7 |
> > Since I'm not familiar with Gentoo's practice in dealing with |
8 |
> > security problems I got curious about the following case. |
9 |
> > Yesterday a Secunia advisory [1] about pidgin was brought to my |
10 |
> > attention. The solution offered by the up-streams is upgrading to |
11 |
> > version 2.5.6, while the latest version in portage is "~2.5.5-r1". |
12 |
> > |
13 |
> > As I see it, there are three possibilities: |
14 |
> > 1) even older, the version in Gentoo is not affected, because the |
15 |
> > maintainers had taken care of it (too optimistic?) |
16 |
> > 2) Gentoo installations are still vulnerable to the bugs |
17 |
> > described in the advisory and nobody knows about it (quite |
18 |
> > disturbing) 3) Gentoo maintainers are working on it, but still not |
19 |
> > ready |
20 |
> > |
21 |
> > Which one is it? |
22 |
> > |
23 |
> > |
24 |
> > [1] [SA35194] http://secunia.com/advisories/35194/ |
25 |
> > |
26 |
> > |
27 |
> > |
28 |
> It's in portage, sync your tree and check again. I just installed |
29 |
> Pidgin 2.5.6 last night. |
30 |
> |
31 |
|
32 |
I guess the mirror I'm using is not up-to-date and they will get a |
33 |
report about it, |
34 |
|
35 |
Thanks! |
36 |
|
37 |
-- |
38 |
Best regards, |
39 |
Daniel |