Bug 7068 - libgnomesu missing update for security issue CVE-2011-1946
Summary: libgnomesu missing update for security issue CVE-2011-1946
Status: RESOLVED WONTFIX
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 2
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Olav Vitters
QA Contact:
URL: http://lwn.net/Vulnerabilities/449433/
Whiteboard:
Keywords:
Depends on: 8097
Blocks:
  Show dependency treegraph
 
Reported: 2012-08-15 00:16 CEST by David Walser
Modified: 2012-12-21 00:10 CET (History)
5 users (show)

See Also:
Source RPM: libgnomesu-1.0.0-7.mga2.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-08-15 00:16:26 CEST
OpenSuSE has issued an advisory on June 24, 2011:
http://lists.opensuse.org/opensuse-updates/2011-06/msg00041.html

Mageia 1 and Mageia 2 are also affected.
David Walser 2012-08-15 00:16:39 CEST

CC: (none) => olav
Whiteboard: (none) => MGA2TOO, MGA1TOO

David Walser 2012-08-15 00:20:20 CEST

Assignee: bugsquad => olav

Comment 1 David Walser 2012-08-15 01:23:30 CEST
OpenSuSE's patch doesn't apply directly in our package, as they have a ton of other patches (and we have a few of our own), so the code is quite a bit different.  Re-diffing it may be non-trivial.
David Walser 2012-10-10 00:45:32 CEST

CC: (none) => oe

Comment 2 David Walser 2012-12-05 19:18:15 CET
urpmq says only clamtk requires libgnomesu, and Fedora does not have libgnomesu.

Damien, can you remove the requires from clamtk so that we can drop this package?

It is obsolete and unmaintained upstream since 2005.

CC: (none) => mageia

Comment 3 Damien Lallement 2012-12-06 17:12:11 CET
Done for cauldron.
For 1, I guess it's too late...
Will do it on 2 ASAP, I've got another request on clamtk on 2.
Comment 4 David Walser 2012-12-06 17:45:05 CET
Thanks Damien.

Sysadmins, could you please remove the obsolete and no longer required "libgnomesu" package from Cauldron?

Removing MGA1TOO from the whiteboard due to EOL.

CC: (none) => sysadmin-bugs
Depends on: (none) => 8097
Whiteboard: MGA2TOO, MGA1TOO => MGA2TOO

Comment 5 Damien Lallement 2012-12-07 19:08:20 CET
FYI: http://svnweb.mageia.org/packages?view=revision&revision=327915
So, clamtk-4.43-1.mga2 does not require "gnomesu" anymore.
Comment 6 Bogdan Gruescu 2012-12-09 19:07:44 CET
@ David Walser

It's harmless, but I think you forgot something to add in task-obsolete-38.mga3 as (at least) lib64gnomesu-devel is still available on mirrors:

Sorry, the following package cannot be selected:

- lib64gnomesu-devel-1.0.0-7.mga2.x86_64 (due to unsatisfied lib64gnomesu0[== 1.0.0-7.mga2])

CC: (none) => gruescubogdan

Comment 7 David Walser 2012-12-09 19:58:12 CET
I didn't think there was supposed to be a 64 in the devel package name.

Thanks for the notice!
Comment 8 David Walser 2012-12-21 00:10:30 CET
Package removed from Cauldron.

Probably can't be fixed for Mageia 2, but with the clamtk update, it is no longer required by anything, so users can remove it from their systems.

Marking as WONTFIX.

Status: NEW => RESOLVED
Version: Cauldron => 2
Resolution: (none) => WONTFIX
Whiteboard: MGA2TOO => (none)


Note You need to log in before you can comment on or make changes to this bug.