Security Advisories mismatch?

Anything that pertains to Entropy, Equo or Sulfur

Moderator: Moderators

Security Advisories mismatch?

Postby pstolowski » Fri Jul 11, 2008 11:19

Hello,

I've noticed a mismatch between security advisories displayed by equo and glsa-check and moreover, equo security advisor seems to not detect a package updated with emerge.
The problem:
1. I had libvorbis-1.2.0 installed (the version included on Sabayon 3.5 DVD).
2. libvorbis < 1.2.1_rc1 was listed as vulnerable by both glsa-check and equo security list
3. there was no update available in entropy repo, so I emerged fresh libvorbis-1.2.1_rc1 with 'emerge libvorbis'.
4. I've now a fresh libvorbis and refreshed equo security advisories list, but equo still lists my libvorbis as affected, i.e.

Code: Select all
 # equery list -i libvorbis
[ Searching for package 'libvorbis' in all categories among: ]
 * installed packages
[I--] [  ] media-libs/libvorbis-1.2.1_rc1 (0)

# equo security update

# equo security list --affected | grep vorbis
>> [GLSA:200806-09:A][<1.2.1_rc1] media-libs/libvorbis: libvorbis: Multiple vulnerabilities

#  glsa-check -l|grep -i 200806-09
[A] means this GLSA was already applied,
[U] means the system is not affected and
[N] indicates that the system might be affected.

200806-09 [U] libvorbis: Multiple vulnerabilities ( media-libs/libvorbis )


So, I have libvorbis-1.2.0_rc1 but equo security still lists is as affected, while glsa-check doesn't complain. Is this a bug or am I missing something?

Thanks
pstolowski
Baby Hen
 
Posts: 11
Joined: Tue Jul 08, 2008 12:16

Re: Security Advisories mismatch?

Postby lxnay » Fri Jul 11, 2008 13:19

Code: Select all
equo database gentoosync
Image
Join us on IRC (chat.freenode.net #sabayon or WebChat)
Submit bugs to our Bug Tracker
Follow me on Twitter
Add me on Facebook
Add me on Google+
lxnay
Land Owner
 
Posts: 3415
Joined: Thu Oct 13, 2005 23:16
Location: Italy

Re: Security Advisories mismatch?

Postby pstolowski » Fri Jul 11, 2008 13:35

lxnay wrote:
Code: Select all
equo database gentoosync


Thanks :). Is this also performed automatically at some point, or do I need to do it manually each time after emering something?

Pawel

PS. equo should have a man page ;)
pstolowski
Baby Hen
 
Posts: 11
Joined: Tue Jul 08, 2008 12:16


Return to Entropy|Equo|Rigo Package Managers

Who is online

Users browsing this forum: No registered users and 1 guest