--------------------------------------------------------------------------- Gentoo Weekly Newsletter http://www.gentoo.org/news/en/gwn/current.xml This is the Gentoo Weekly Newsletter for the week of September 22nd, 2003. --------------------------------------------------------------------------- ============== 1. Gentoo News ============== Summary ------- * Gentoo 1.4 maintenance release 1 for x86 * Experimental IA-64 stage1 available Gentoo 1.4 maintenance release 1 for x86 ---------------------------------------- New 20030911 builds of Gentoo 1.4 are now available on mirrors[1] and at the Gentoo Store[2] so this may be a good time to reburn your CDs or to order some copies of the LiveCDs. This maintenance build has the same functionality as the 1.4 release but fixes many bugs. Also, if you installed Gentoo with the 1.4 release there's no need to worry because the releases are only relevant for the LiveCDs and GRPs; run emerge rsync; emerge -u world and your Gentoo system will be as up-to-date as anyone else's. 1. http://www.gentoo.org/main/en/mirrors.xml 2. http://store.gentoo.org/ Experimental IA-64 stage1 available ----------------------------------- The IA-64 port can now be fully built from stage1, and an experimental IA-64 stage1 tarball is now available under experimental/ia64. There's no LiveCD, but users are encouraged to try building a system, see how it works, and submit bugs to Bugzilla[3]. 3. http://bugs.gentoo.org/ ================== 2. Gentoo Security ================== Summary ------- * GLSA: mysql * GLSA: exim * GLSA: pine * GLSA: openssh * GLSA: sendmail GLSA: mysql ----------- Quote from advisory: "Anyone with global administrative privileges on a MySQL server may execute arbitrary code even on a host he isn't supposed to have a shell on, with the privileges of the system account running the MySQL server." * Severity: High - execute arbitrary code. * Packages Affected: =mysql-4.0.14-r2(masked) * Rectification: emerge sync; emerge dev-db/mysql/; emerge clean * GLSA Announcement[4] 4. http://marc.theaimsgroup.com/?l=gentoo-announce&m=106362878312500&w=2 GLSA: exim ---------- "There's a heap overflow in all versions of exim3 and exim4 prior to version 4.21. It can be exercised by anyone who can make an SMTP connection to the exim daemon." * Severity: Low - heap overflow * Packages Affected: - Editor AJ Armstrong - Contributor Brian Downey - Contributor Cal Evans - Contributor Chris Gavin - Contributor Luke Giuliani - Contributor Shawn Jonnet - Contributor Michael Kohl - Contributor Kurt Lieber - Contributor Rafael Cordones Marcos - Contributor David Narayan - Contributor Gerald J Normandin Jr. - Contributor Ulrich Plate - Contributor Mathy Vanvoorden - Dutch Translation Hendrik Eeckhaut - Dutch Translation Jorn Eilander - Dutch Translation Bernard Kerckenaere - Dutch Translation Peter ter Borg - Dutch Translation Jochen Maes - Dutch Translation Roderick Goessen - Dutch Translation Gerard van den Berg - Dutch Translation Matthieu Montaudouin - French Translation Martin Prieto - French Translation Antoine Raillon - French Translation Sebastien Cevey - French Translation Jean-Christophe Choisy - French Translation Steffen Lassahn - German Translation Matthias F. Brandstetter - German Translation Thomas Raschbacher - German Translation Klaus-J. Wolf - German Translation Marco Mascherpa - Italian Translation Claudio Merloni - Italian Translation Christian Apolloni - Italian Translation Stefano Lucidi - Italian Translation Yoshiaki Hagihara - Japanese Translation Katsuyuki Konno - Japanese Translation Yuji Carlos Kosugi - Japanese Translation Yasunori Fukudome - Japanese Translation Takashi Ota <088@t.email.ne.jp> - Japanese Translation Radoslaw Janeczko - Polish Translation Lukasz Strzygowski - Polish Translation Michal Drobek - Polish Translation Adam Lyjak - Polish Translation Krzysztof Klimonda - Polish Translation Atila "Jedi" Bohlke Vasconcelos - Portuguese (Brazil) Translation Eduardo Belloti - Portuguese (Brazil) Translation Jo??o Rafael Moraes Nicola - Portuguese (Brazil) Translation Marcelo Gon??alves de Azambuja - Portuguese (Brazil) Translation Otavio Rodolfo Piske - Portuguese (Brazil) Translation Pablo N. Hess -- NatuNobilis - Portuguese (Brazil) Translation Pedro de Medeiros - Portuguese (Brazil) Translation Ventura Barbeiro - Portuguese (Brazil) Translation Bruno Ferreira - Portuguese (Portugal) Translation Gustavo Felisberto - Portuguese (Portugal) Translation Jos?? Costa - Portuguese (Portugal) Translation Luis Medina - Portuguese (Portugal) Translation Ricardo Loureiro - Portuguese (Portugal) Translation Sergey Galkin - Russian Translator Sergey Kuleshov - Russian Translator Alex Spirin - Russian Translator Dmitry Suzdalev - Russian Translator Anton Vorovatov - Russian Translator Denis Zaletov - Russian Translator Lanark - Spanish Translation Fernando J. Pereda - Spanish Translation Lluis Peinado Cifuentes - Spanish Translation Zephryn Xirdal T - Spanish Translation Guillermo Juarez - Spanish Translation Jes??s Garc??a Crespo - Spanish Translation Carlos Castillo - Spanish Translation Julio Castillo - Spanish Translation Sergio G??mez - Spanish Translation Aycan Irican - Turkish Translation Bugra Cakir - Turkish Translation Cagil Seker - Turkish Translation Emre Kazdagli - Turkish Translation Evrim Ulu - Turkish Translation Gursel Kaynak - Turkish Translation