public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed
@ 2006-05-29 16:39 Stefan Cornelius
  2006-05-30 14:22 ` Stefan Cornelius
  0 siblings, 1 reply; 2+ messages in thread
From: Stefan Cornelius @ 2006-05-29 16:39 UTC (permalink / raw
  To: gentoo-dev

Hi Gang,

net-www/awstats is masked because it has open security issues (including
remote code execution), see bug #130487 for details. Version 6.6 was
made to fix it, but unfortunately this version is not working at all
(see bug #134296), so we are trapped between unusable and vulnerable
versions.

Jakub made a patch for version 6.5 to fix this vulnerabilities, but that
very patch still needs to be incorporated into an ebuild and commited as
revbump.

So, if anyone volunteers to step up and revbump 6.5 with patch (or fix
6.6 so that it's usable), please don't hesitate. It would be also cool
to have a new maintainer for this one, since ka0ttic seems to be
missing.


Thanks in advance,

Stefan 'DerCorny' Cornelius

-- 
gentoo-dev@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed
  2006-05-29 16:39 [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed Stefan Cornelius
@ 2006-05-30 14:22 ` Stefan Cornelius
  0 siblings, 0 replies; 2+ messages in thread
From: Stefan Cornelius @ 2006-05-30 14:22 UTC (permalink / raw
  To: gentoo-dev

CHTEKK does this one, thanks.


> Hi Gang,
> 
> net-www/awstats is masked because it has open security issues (including
> remote code execution), see bug #130487 for details. Version 6.6 was
> made to fix it, but unfortunately this version is not working at all
> (see bug #134296), so we are trapped between unusable and vulnerable
> versions.
> 
> Jakub made a patch for version 6.5 to fix this vulnerabilities, but that
> very patch still needs to be incorporated into an ebuild and commited as
> revbump.
> 
> So, if anyone volunteers to step up and revbump 6.5 with patch (or fix
> 6.6 so that it's usable), please don't hesitate. It would be also cool
> to have a new maintainer for this one, since ka0ttic seems to be
> missing.
> 
> 
> Thanks in advance,
> 
> Stefan 'DerCorny' Cornelius
> 

-- 
gentoo-dev@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-05-30 14:22 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-29 16:39 [gentoo-dev] net-www/awstats: security issues, revbump (and probably maintainer) needed Stefan Cornelius
2006-05-30 14:22 ` Stefan Cornelius

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox