From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([69.77.167.62] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1JCJ8A-0005AQ-33 for garchives@archives.gentoo.org; Tue, 08 Jan 2008 18:24:54 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 756B2E0A98; Tue, 8 Jan 2008 18:24:51 +0000 (UTC) Received: from bombastor.soundbomb.net (bombastor.soundbomb.net [213.41.185.190]) by pigeon.gentoo.org (Postfix) with ESMTP id A63FAE0A98 for ; Tue, 8 Jan 2008 18:24:50 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by bombastor.soundbomb.net (Postfix) with ESMTP id BCD4ED40C0 for ; Tue, 8 Jan 2008 19:24:49 +0100 (CET) X-Virus-Scanned: amavisd-new at soundbomb.net Received: from bombastor.soundbomb.net ([127.0.0.1]) by localhost (bombastor.soundbomb.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7jb9KSeRcQPq for ; Tue, 8 Jan 2008 19:24:47 +0100 (CET) Received: from [10.1.10.3] (sdblt001.soundbomb.local [10.1.10.3]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by bombastor.soundbomb.net (Postfix) with ESMTP id 97D46D4063 for ; Tue, 8 Jan 2008 19:24:47 +0100 (CET) Message-ID: <4783BFEA.4000605@soundbomb.net> Date: Tue, 08 Jan 2008 19:24:42 +0100 From: mRyOuNg User-Agent: Thunderbird 2.0.0.9 (X11/20071229) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-server@lists.gentoo.org Reply-to: gentoo-server@lists.gentoo.org MIME-Version: 1.0 To: gentoo-server@lists.gentoo.org Subject: Re: [gentoo-server] what happend to GLSA ? References: <20080108180609.M10042@lutel.pl> In-Reply-To: <20080108180609.M10042@lutel.pl> X-Enigmail-Version: 0.95.5 OpenPGP: id=F399E2E5; url=http://mryoung.soundbomb.net/yng_bbt_pubgpg.asc Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig9FFD3AF5258C826673DE597E" X-Archives-Salt: 0614ea01-aa00-40a9-a436-cd71b294a271 X-Archives-Hash: 52e2f01d884a90604704fd020a45c68a This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig9FFD3AF5258C826673DE597E Content-Type: text/plain; charset=ISO-8859-2 Content-Transfer-Encoding: quoted-printable Tomasz Lutelmowski wrote: > The GLSA is not updating since 2007-12-25... >=20 > xxx etc # glsa-check -l | tail > [A] means this GLSA was already applied, > [U] means the system is not affected and > [N] indicates that the system might be affected. >=20 > 200712-16 [U] Exiv2: Integer overflow ( media-gfx/exiv2 ) > 200712-17 [U] exiftags: Multiple vulnerabilities ( media-gfx/exiftags )= > 200712-18 [U] Multi-Threaded DAAP Daemon: Multiple vulnerabilities ( me= dia- > sound/mt-daapd ) > 200712-19 [U] Syslog-ng: Denial of Service ( app-admin/syslog-ng ) > 200712-20 [U] ClamAV: Multiple vulnerabilities ( app-antivirus/clamav )= > 200712-21 [U] Mozilla Firefox, SeaMonkey: Multiple vulnerabilities ( ww= w- > client/seamonkey www-client/mozilla-firefox-bin www-client/mozilla- > firefox ... ) > 200712-22 [U] Opera: Multiple vulnerabilities ( www-client/opera ) > 200712-23 [U] Wireshark: Multiple vulnerabilities ( net-analyzer/wiresh= ark ) > 200712-24 [U] AMD64 x86 emulation GTK+ library: User-assisted execution= of=20 > arbitrary code ( app-emulation/emul-linux-x86-gtklibs ) > 200712-25 [U] OpenOffice.org: User-assisted arbitrary code execution ( = app- > office/openoffice app-office/openoffice-bin dev-db/hsqldb ) >=20 > Is it temporary issue or Gentoo got new way of tracking vulnerabilities= ? >=20 > Regards, > TOmek >=20 Hi there ... Hmm, if i remember well, the last number has nothing todo with the day ..= =2E 200712-25 means ... 25th Security Advisory during December 2007 Maybe i'm wrong, but one sure thing is that the last number as nothing to do with the day ... for example # glsa-check -d 200712-17 | grep "Announced" Announced on: December 29, 2007 cya! --=20 =2E mRyOuNg :: [ SoundBomb . Syn[Rj] ] . mail: mryoung@soundbomb.net web : mryoung.soundbomb.net --------------enig9FFD3AF5258C826673DE597E Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFHg7/uF8u0XPOZ4uURAqSbAJ9KcsEInWsUc9cBd3688syLGru9EwCdG2/V M8/lJoxRe2Kt5GhOZnMVh/E= =eDDq -----END PGP SIGNATURE----- --------------enig9FFD3AF5258C826673DE597E-- -- gentoo-server@lists.gentoo.org mailing list