Gentoo Weekly Newsletter 19 June 2006

Lars Weiler <[email protected]> Tue, 20 Jun 2006 22:17:46 +0200
Newsgroups gmane.linux.gentoo.weekly-news
Message-ID <[email protected]>
-------------------------------------------------------------------------=
--
Gentoo Weekly Newsletter
http://www.gentoo.org/news/en/gwn/current.xml
This is the Gentoo Weekly Newsletter for the week of 19 June 2006.
-------------------------------------------------------------------------=
--

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
1. Gentoo news
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Userrel wants YOU! - User Representatives Nominations
-----------------------------------------------------

As one of the major distributions at the moment, Gentoo's organisation ca=
n
be a fiendishly complicated thing to understand, and it can be difficult
to know how you can help out. To this end, we have created the position o=
f
=E2=80=98user representative=E2=80=99, and would like to take this opport=
unity to explain
something about the role.

=E2=80=9CKnow thy users=E2=80=9D is popular advice, and often we attempt =
to achieve this
by consultation with one or more users. People will tend to err towards
the idea of the statistical =E2=80=98average user=E2=80=99 =E2=80=93 one =
speaks for all. Although
this approach is a simple and oftentimes effective way to find a
representative user, the results are only valuable if the user base, thei=
r
day-to-day tasks and work settings are homogeneous. If there are
significant variations, this approach will fail to support some users, an=
d
can result in a product that does not meet their needs. It relies heavily
upon having selected the most important user attributes for sampling and
consultation, and can easily tempt us to think that knowing the
characteristics of the average user, we need not consult with them. In
this way it discourages us from challenging our own assumptions, and may
deny us a source of valuable information that could prevent mistakes.

The User Relations project focuses on bridging the gap between the
developer and user communities, actively seeking out ways to improve
communications between the two and encourage user involvement. It aims to
ensure that high standards are met, and to work closely with other user
focused projects to produce the best distribution possible for the user
base. To this end, it is looking for user representatives to help in this
quest.

The project has decided that 5 user representatives should be enough to
provide a sufficiently diverse range of opinions and interests while
avoiding the issues associated with having too many. Nominations are now
open; see this forum thread[1] for more information and to nominate any
users you would like to see considered for the position.

 1. http://forums.gentoo.org/viewtopic-t-470136.html

What does a User Representative do?

Becoming a user representative may take some time, energy and commitment,
but it can also be very rewarding. The role of user representative
involves:

 * Present the views, and represent the interests, of all elements of our
diverse user base.
 * Be a =E2=80=98critical friend=E2=80=99 to the User Relations project, =
offering
alternative opinions and perspectives, and challenging the assumptions of
all involved wherever appropriate.
 * Engage positively with developers and Gentoo projects
 * Interact with a wide range of groups and individuals to find out what
our users think, and what they would like to see happening.
 * Suggest ways in which other users could be engaged and involved in the
project, in planning and delivering information and elsewhere.
 * Channel information back to the users regarding proceedings of and
decisions made in meetings.

If you were thinking of becoming a user representative, you will not be
left alone. The user relations project will be there to support you, and
you will be assigned a current developer as a point of contact with whom
you can discuss any questions or concerns about your role or the group as
a whole.

Why become a user representative?

 * You will have the opportunity to influence how information, news, and
support are delivered to users, and to ensure that they are organised in
the best way possible for all our users.
 * You will gain experience as an advocate for the user community, and
useful knowledge and skills that can be applied in many areas of life.
 * It is a great way to give something back to the community, and to get
involved as a user.
 * You will have the chance to meet and get to know other users and
developers.

What makes a good user representative?

The ideal user representative would:

 * Be willing to network with a wide range of other users.
 * Be seen as approachable by others, so that people will be open about
their views. Be non-judgemental and show sensitivity towards what may be
difficult issues.
 * Work constructively with developers and staff. Not be scared or
intimidated by developers, but to view them as people doing the best they
can within constraints. Should it be necessary to challenge them, do so i=
n
a supportive manner wherever possible.
 * Be able to negotiate, to make the case for a particular course of
action, and willing to compromise where appropriate.
 * Be able to step outside of his/her own experience, and be able to argu=
e
a viewpoint with which you may not fully agree.
 * Present users' views with confidence, and not be afraid to raise issue=
s
about the role or the workings of the project.

Where can I learn more?

We hope that most questions will have been answered above, but for any
more information please do get in touch with the user relations team by
one of the following methods:

 * gentoo-userrel mailing list -- to subscribe, send a blank email to
[email protected]; the address to post is then
[email protected].
 * By email to [email protected].
 * In IRC: #gentoo-userrel[2] on irc.freenode.net.
 2. irc://irc.freenode.net/gentoo-userrel


Other ways to get involved

There are a number of areas in which interested users can contribute to
Gentoo:

 * Gentoo Linux Development team: Prospective developers are encouraged t=
o
become active on bugzilla[3]. The bug reports are monitored by developmen=
t
recruiters, so start squashing bugs and you will become noticed.
 * Gentoo Bugdays: On the first Saturday of each month both developers an=
d
users gather in #gentoo-bugs[4] on irc.freenode.net[5] where bugs are
tested, discussed and resolved. Bugdays offer a great way for developers
and users to work together and get to know each other. It also provides a=
n
opportunity for potential developers to be scouted. For further
information the Bugday team[6] can be contacted.
 * Gentoo Linux Documentation team: The team provides users with clear an=
d
concise documentation. It consists of Writers/Editors and Translators for
various languages. For more information on joining take a look at the
Gentoo Linux Documentation Policy.[7]
 * Gentoo Weekly Newsletter: If you would like to offer your help to the
GWN team as a contributor or translator then contact information can be
found in the Gentoo Weekly Newsletter Overview.
 * #gentoo IRC Channel: Knowledgeable users are encouraged to come and
help out in #gentoo[8] on irc.freenode.net.
 * #gentoo-dev-help IRC Channel: Anyone wanting to know more about ebuild
writing and/or Gentoo development is welcome to come and ask in
#gentoo-dev-help[9] on Freenode, where developers and other users are
waiting to help.
 3. bugs.gentoo.org
 4. irc://irc.freenode.net/gentoo-bugs
 5. http://irc.freenode.net
 6. http://bugday.gentoo.org/
 7. http://www.gentoo.org/proj/en/gdp/doc/doc-policy.xml
 8. irc://irc.freenode.net/gentoo
 9. irc://irc.freenode.net/gentoo-dev-help


Project Sunrise - Gentoo User Overlay
-------------------------------------

Last week there was the announcement of an overlay for user-submitted
ebuilds. This was intended to help users to find and use ebuilds that for
now only exist in Gentoo Bugzilla and to ensure that these ebuilds adhere
to quality standards. Also it might offer a good environment for
recruiting new ebuild developers from the user community.

Giving commit access to this repository to trusted users has caused some
very intense debates, centering mostly around policies and potential
problems from malicious users. During the council meeting on June 16th it
was decided that while the idea is quite good the execution was lacking.

As a consequence the Sunrise overlay has been suspended from official
Gentoo hardware, but it does continue on gentoo-sunrise.org[10] as an
unofficial project.

 10. http://gentoo-sunrise.org

Sunrise is looking for more users to add ebuilds from bugzilla to the
overlay. You can find more information about Sunrise and its goals on  th=
e
project page[11] and have a look at the FAQ[12] as well as the actual
overlay.[13] Feel free to visit the IRC channel - #gentoo-sunrise[14] on
irc.freenode.net awaits you!

 11. http://www.gentoo.org/proj/en/sunrise
 12. http://gentoo-sunrise.org/cgi-bin/trac.cgi/wiki/SunriseFaq
 13. http://gentoo-sunrise.org/cgi-bin/trac.cgi/browser
 14. irc://irc.freenode.net/gentoo-sunrise

Java 1.5 progress and changes in Java handling
----------------------------------------------

As some might have noticed, Java 1.5 has been package.masked for some tim=
e
now. There are a number of issues introduced with 1.5 that have kept it i=
n
package.mask. Please see the Java 1.5 FAQ[15] for more details.

 15. http://www.gentoo.org/proj/en/java/tiger-faq.xml

About a year ago, work was begun on improving our part of the build syste=
m
(read: Java related eclasses and our java-config tool) in a way to make i=
t
much more flexible in general, but specifically improve it to get around
the known issues. It took about six months to fully develop.
Unfortunately, the new system was not quite a drop-in replacement. So, it
took from then until now to determine how to migrate from the current
system to the new one in a sane way.

But now we are ready to move to the new system.

Highlights of the new system:

 * Ability to switch the current VM on the fly
 * Changes to the user and system VM take effect immediately, and no
longer are tied to the shell environment (ie no more running env-update &=
&
source /etc/profile after switching the sytem VM)
 * Now has the concept of a =E2=80=98build VM=E2=80=99, which is used to =
emerge packages,
and is configured independently of the system VM.
 * For each version of Java, ie 1.3, 1.4, 1.5, etc, the build vm can
configured as to which vendor and version of a VM to use
 * The VM at emerge time will be switched on the fly according to its
configuration, as well as the dependency of the package. For example, som=
e
packages won't compile with 1.5. In these cases, a 1.4 VM will be used at
build time.
 * Java packages which build with ant will have their build.xml rewritten
at build time, in order to ensure that the correct version of Java
bytecode is compiled.
 * We'll be able to unmask Java 1.5 soon, and be able to handle Java 1.6
when it comes out this fall.

The new system is currently being discussed on the gentoo-dev
mailinglist[16], and assuming no major issues come up, will likely make
their way into the tree in the next few weeks.

 16. http://article.gmane.org/gmane.linux.gentoo.devel/39547

nss_ldap breakage and how to prevent it
---------------------------------------

With the upgrade to nss_ldap-249 and later many users found their system
in an almost unusable state: Upon boot it could take an extremely long
time (up to an hour) to get to a login prompt. This is caused by a small
change in behaviour: What used to be a fixed timeout is now a configurabl=
e
amount of attempts with increasing time between them. Information how to
fix this problem can be found here:

 * Upgrading/using nss_ldap/nss_mysql/nss_nis/nss... and not breaking you=
r
system[17]
 17. http://robbat2.livejournal.com/199841.html


Hungarian GWN translators
-------------------------

Recently a Hungarian GWN translation has been considered. Right now we ar=
e
looking for some translators to help with the task - if you are intereste=
d
please send a notice to [email protected]. Many thanks in advance!

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
2. Heard in the community
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

planet.gentoo.org
-----------------

Gentoo multimedia FAQ

After seeing lots of similar questions on the Gentoo Forums and the
#gentoo IRC channel Steve Dibb started collecting questions for a
multimedia FAQ. If you like to see common questions being answered in his
FAQ let him know[18].

 18. [email protected]

 * Gentoo multimedia FAQ[19]
 19. http://wonkabar.org/blog/?p=3D96


gentoo-dev
----------

Project Sunrise

The User Overlay project by Stefan Schweizer[20] and Markus Ullmann[21]
has caused much discussion and has been suspended for now. The following
threads spawned from this announcement:

 20. [email protected]
 21. [email protected]

 * [ANNOUNCE] Project Sunrise - Gentoo User Overlay [22]
 * Project Sunrice: arch team perspective [23]
 * What is "official"? [24]
 * Sunrise Project -- Open questions post requirement [25]
 * Project Sunrise -- Proposal [26]
 * Project Sunrise overlay suspended pending Council resolution[27]
 * A heretical thought? Blessing project sunrise as an almost-fork. [28]
 * Sunrise: way forward, semi-official, review[29]
 22. http://thread.gmane.org/gmane.linux.gentoo.devel/38898
 23. http://thread.gmane.org/gmane.linux.gentoo.devel/39002
 24. http://thread.gmane.org/gmane.linux.gentoo.devel/39013
 25. http://thread.gmane.org/gmane.linux.gentoo.devel/39043
 26. http://thread.gmane.org/gmane.linux.gentoo.devel/39166
 27. http://thread.gmane.org/gmane.linux.gentoo.devel/39250
 28. http://thread.gmane.org/gmane.linux.gentoo.devel/39301
 29. http://thread.gmane.org/gmane.linux.gentoo.devel/39512


Defining the Tree: a proto-GLEP.

Stephen Bennett[30] starts a discussion that has its roots in the
=E2=80=9Calternative package manager=E2=80=9D threads of the last weeks. =
One issue that
was often mentioned is the lack of a formal specification of the ebuild
format, environment and many other small details. So Stephen intends to
write, together with the portage team and other interested developers, a
full specification if there is enough interest and support within the
developer community =E2=80=93 and, almost obviously, this idea is almost
universally accepted as a good thing.

 30. [email protected]

 * Defining the Tree: a proto-GLEP [31]
 31. http://thread.gmane.org/gmane.linux.gentoo.devel/39259


Profiles Part 2

Following on from the lengthy and at times heated discussion in the
Paludis and Profiles[32] thread mentioned here two weeks ago, Stephen
Bennett[33] sent a new proposal to the list to make life easier for
alternative package managers in the tree. This version is
package-manager-agnostic and met with a much more positive response and n=
o
visible opposition. As things stand, it is set to be implemented at some
point after the 2006.1 release.

 32. http://thread.gmane.org/gmane.linux.gentoo.devel/38016
 33. [email protected]

 * Profiles Part 2[34]
 34. http://thread.gmane.org/gmane.linux.gentoo.devel/39249


GLEP 42 Revisited

GLEP 42, =E2=80=9CCritical News Reporting=E2=80=9D, has been waiting in a=
 sort of limbo
since its author left the Gentoo project. However, Stephen Bennett has no=
w
taken over sponsorship of it, and sent it to the mailing list again. The
GLEP seems to have fairly widespread support, and should be sent to the
Gentoo Council for approval in the near future.

 * GLEP 42 (News) revisited[35]
 35. http://thread.gmane.org/gmane.linux.gentoo.devel/39258


GWN issues

Under the slightly unintuitive title "July Council Meeting: Requested
Agenda Item" Christel Dahlskjaer[36] starts a discussion about the state
of the GWN. There were some issues with past GWNs, especially with the
limited availability of Ulrich Plate[37]. As a positive side effect
Christel and some other devs have joined the GWN and will try to help
where they can.

 36. [email protected]
 37. [email protected]

 * July Council Meeting: Requested Agenda Item [38]
 38. http://thread.gmane.org/gmane.linux.gentoo.devel/39141


[RFC] i18n project

Diego 'Flameeyes' Petten=C3=B2[39] asks for some input on one of his exce=
llent
ideas: An internationalization (i18n) project to make the life of our
non-English users easier. Initial goals include translating error message=
s
of Gentoo-developed applications and the respective manpages but the real
span is yet to be defined.

 39. [email protected]

 * [RFC] i18n project [40]
 40. http://thread.gmane.org/gmane.linux.gentoo.devel/39131


=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
3. Gentoo International
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Germany: FrOSCon, Bonn/Rhein-Sieg
---------------------------------

Gentoo Developer Tobias Scherbaum[41] will give two talks at the first
Free and Open Source Software Conference[42] taking place at the
University of Applied Sciences Bonn-Rhein-Sieg next weekend. His first
talk is an introduction to Gentoo where he talks about Gentoo's history,
Gentoo's current state and further development. The second talk covers
Gentoo's usage in business environments and demonstrates Gentoo's
strengths, but also areas where Gentoo needs to evolve. For more details
check the FrOSCon lectures website[43].

 41. [email protected]
 42. http://www.froscon.org
 43. http://programm.froscon.org

Gentoo Summer Camp 2006
-----------------------

The second Gentoo Summer Camp will take place on 26 and 27 august on a
campground next to the fourth largest lake in Lower Saxony called =E2=80=9C=
Grosses
Meer=E2=80=9D. While this claims to be a Gentoo camp, the organization te=
am around
Forums moderator  Uwe H=C3=B6lzel[44] focusses mainly on social aspects.
Playing mini-golf, having barbeque or just discovering the nature is
preferred over hacking. For everyone who is interested in attending, the
GSC team already set up a web page[45] which provides further information
and a forum.

 44. http://forums.gentoo.org/profile.php?mode=3Dviewprofile&u=3D18822
 45. http://gsc2006.nachtnebelnelken.de/

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
4. Gentoo in the press
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

gentoo.de: Guide to Portage 2.1 (13 June 2006)
----------------------------------------------

The German community website gentoo.de published an article on new
features and changed behaviour in Portage 2.1[46]. Author Tobias
Scherbaum[47] includes an overview, but also gives practical examples on
how these new features can be used to improve your Gentoo experience. The
article is currently only available in German, an English translation can
be done on short notice if some people indicate interest.

 46. http://www.gentoo.de/main/de/portage-2.1.xml
 47. [email protected]

Rapid GUI Development with QtRuby
---------------------------------

Gentoo Developer Caleb Tennis[48] has recently published a book called
=E2=80=9CRapid GUI Development with QtRuby=E2=80=9D. It is available as P=
DF on the
Pragmatic Programmer Website[49]. While it does assume some basic working
knowledge of Ruby it is intended to be easy to read and informative even
for people not yet familiar with Qt.

 48. [email protected]
 49. http://pragmaticprogrammer.com/titles/ctrubyqt/index.html

Although it is not Gentoo-specific all testing of programs for this book
happened on Gentoo. The QtRuby bindings can be emerged with emerge qtruby=
,
the KDE extension Korundum can also be emerged with emerge korundum, so
Gentoo users will have it especially easy if they wish to play around wit=
h
these programs.

Caleb Tennis has been a Gentoo developer for three years now and is part
of the Ruby, Qt and KDE herds.

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
5. Tips and tricks
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Exploring portage features
--------------------------

The new release of Portage 2.1 brings many features and improvements.
While most of them are documented in the example make.conf and the portag=
e
man page they may not be obvious to most users, so we will show how to us=
e
some of these features.

All the features have to be set in /etc/make.conf.

Portage is now able to download some package's source code while compilin=
g
another. This can considerably reduce installation time when emerging man=
y
packages. There's no need to run emerge --fetchonly while doing a normal
emerge anymore. You just have to add the following option:

+------------------------------------------------------------------------=
-+
| Code Listing 5.1:                                                      =
 |
| Setting parallel-fetch in /etc/make.conf                               =
 |
+------------------------------------------------------------------------=
-+
|                                                                        =
 |
|FEATURES=3D"parallel-fetch"                                             =
   |
|                                                                        =
 |
+------------------------------------------------------------------------=
-+

This feature appears to be non-functional in some of the Portage 2.1
releases, but is expected to be fixed soon.

Another new option to reduce installation time yet a bit more is
confcache. With this new feature portage caches many of the tests
configuration scripts do, thus making execution faster. This comes with
the small risk of caching wrong values, so be warned that this feature is
known to have a few bugs. Since this package is currently keyworded on
most architectures, the required steps to enable it are:

+------------------------------------------------------------------------=
-+
| Code Listing 5.2:                                                      =
 |
| Enabling confcache                                                     =
 |
+------------------------------------------------------------------------=
-+
|                                                                        =
 |
|Add this in /etc/make.conf                                              =
 |
|FEATURES=3D"confcache"                                                  =
   |
|We need to unmask the package before emerging it                        =
 |
|echo "=3Ddev-utils/confcache-0.4.2-r1 ~arch" \                          =
   |
| >>/etc/portage/package.keywords                                        =
 |
|Installing confcache                                                    =
 |
|emerge -av confcache                                                    =
 |
|On further installations. you'll see stuff like:                        =
 |
|checking for i686-pc-linux-gnu-gcc... (cached) i686-pc-linux-gnu-gcc    =
 |
|checking whether we are using the GNU C compiler...(cached) yes         =
 |
|checking whether i686-pc-linux-gnu-gcc accepts -g... (cached) yes       =
 |
|                                                                        =
 |
+------------------------------------------------------------------------=
-+

Another important new feature is the ability to log all the messages
ebuilds print. Which messages to log and how to do it is configurable. Fo=
r
example, to save just the warnings and errors in a separate file for each
package we emerge, you have to add:

+------------------------------------------------------------------------=
-+
| Code Listing 5.3:                                                      =
 |
| Configuring logging features in /etc/make.conf                         =
 |
+------------------------------------------------------------------------=
-+
|                                                                        =
 |
|This sets what to log                                                   =
 |
|PORTAGE_ELOG_CLASSES=3D"warn error log"                                 =
   |
|And this is how to do it                                                =
 |
|PORTAGE_ELOG_SYSTEM=3D"save"                                            =
   |
|                                                                        =
 |
+------------------------------------------------------------------------=
-+

There are many more options like sending log messages via email. Please
check out make.conf.example for further information.

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
6. Gentoo developer moves
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Moves
-----

The following developers recently left the Gentoo project:

 * Chris White*

Adds
----

The following developers recently joined the Gentoo project:

 * Chris White (chriswhite) (random stuff)*

Changes
-------

The following developers recently changed roles within the Gentoo project=
:

 * none this week

Note: Chris White resigned and then retracted his resignation. To show
this change in status he is mentioned both as leaving and newly joining.

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
7. Gentoo security
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

GDM: Privilege escalation
-------------------------

An authentication error in GDM could allow users to gain elevated
privileges.

For more information, please see the GLSA Announcement[50]

 50. http://www.gentoo.org/security/en/glsa/glsa-200606-14.xml

Asterisk: IAX2 video frame buffer overflow
------------------------------------------

Asterisk contains a bug in the IAX2 channel driver making it vulnerable t=
o
the remote execution of arbitrary code.

For more information, please see the GLSA Announcement[51]

 51. http://www.gentoo.org/security/en/glsa/glsa-200606-15.xml

DokuWiki: PHP code injection
----------------------------

A flaw in DokuWiki's spell checker allows for the execution of arbitrary
PHP commands, even without proper authentication.

For more information, please see the GLSA Announcement[52]

 52. http://www.gentoo.org/security/en/glsa/glsa-200606-16.xml

OpenLDAP: Buffer overflow
-------------------------

The OpenLDAP replication server slurpd contains a buffer overflow that
could result in arbitrary code execution.

For more information, please see the GLSA Announcement[53]

 53. http://www.gentoo.org/security/en/glsa/glsa-200606-17.xml

PAM-MySQL: Multiple vulnerabilities
-----------------------------------

Vulnerabilities in PAM-MySQL can lead to a Denial of Service, making it
impossible to log into a machine.

For more information, please see the GLSA Announcement[54]

 54. http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml

Sendmail: Denial of Service
---------------------------

Faulty multipart MIME messages can cause forked Sendmail processes to
crash.

For more information, please see the GLSA Announcement[55]

 55. http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml

Typespeed: Remote execution of arbitrary code
---------------------------------------------

A buffer overflow in the network code of Typespeed can lead to the
execution of arbitrary code.

For more information, please see the GLSA Announcement[56]

 56. http://www.gentoo.org/security/en/glsa/glsa-200606-20.xml

Mozilla Thunderbird: Multiple vulnerabilities
---------------------------------------------

Several vulnerabilities in Mozilla Thunderbird allow cross site scripting=
,
JavaScript privilege escalation and possibly execution of arbitrary code.

For more information, please see the GLSA Announcement[57]

 57. http://www.gentoo.org/security/en/glsa/glsa-200606-21.xml

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
8. Bugzilla
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Summary
-------

 * Statistics
 * Closed bug ranking
 * New bug rankings

Statistics
----------

The Gentoo community uses Bugzilla (bugs.gentoo.org[58]) to record and
track bugs, notifications, suggestions and other interactions with the
development team. Between 12 June 2006 and 19 June 2006, activity on the
site has resulted in:

 58. http://bugs.gentoo.org

 * 710 new bugs during this period
 * 366 bugs closed or resolved during this period
 * 21 previously closed bugs were reopened this period

Of the 10298 currently open bugs: 54 are labeled 'blocker', 138 are
labeled 'critical', and 554 are labeled 'major'.

Closed bug rankings
-------------------

The developers and teams who have closed the most bugs during this period
are:

 * Portage team[59], with 22 closed bugs[60]
 * Gentoo KDE team[61], with 19 closed bugs[62]
 * AMD64 Project[63], with 18 closed bugs[64]
 * Gentoo Security[65], with 16 closed bugs[66]
 * Gentoo Games[67], with 14 closed bugs[68]
 * Xavier Neys[69], with 13 closed bugs[70]
 * Gentoo Linux Gnome Desktop Team[71], with 13 closed bugs[72]
 * Gentoo's Team for Core System packages[73], with 10 closed bugs[74]
 59. [email protected]
 60. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 61. [email protected]
 62. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 63. [email protected]
 64. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 65. [email protected]
 66. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 67. [email protected]
 68. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 69. [email protected]
 70. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 71. [email protected]
 72. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]
 73. [email protected]
 74. http://bugs.gentoo.org/buglist.cgi?bug_status=3DRESOLVED&bug_status=3D=
CLOSED&chfield=3Dbug_status&chfieldfrom=3D2006-06-12&chfieldto=3D2006-06-=
19&resolution=3DFIXED&[email protected]


New bug rankings
----------------

The developers and teams who have been assigned the most new bugs during
this period are:

 * Default Assignee for New Packages[75], with 35 new bugs[76]
 * Default Assignee for Orphaned Packages[77], with 22 new bugs[78]
 * Gentoo's Team for Core System packages[79], with 9 new bugs[80]
 * Jon Hood[81], with 8 new bugs[82]
 * Gentoo Sound Team[83], with 8 new bugs[84]
 * Gentoo Games[85], with 7 new bugs[86]
 * Gentoo Science Related Packages[87], with 6 new bugs[88]
 * Netmon Herd[89], with 6 new bugs[90]
 75. [email protected]
 76. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 77. [email protected]
 78. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 79. [email protected]
 80. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 81. [email protected]
 82. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 83. [email protected]
 84. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 85. [email protected]
 86. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 87. [email protected]
 88. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]
 89. [email protected]
 90. http://bugs.gentoo.org/buglist.cgi?bug_status=3DNEW&bug_status=3DASS=
IGNED&bug_status=3DREOPENED&chfield=3Dassigned_to&chfieldfrom=3D2006-06-1=
2&chfieldto=3D2006-06-19&[email protected]


=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
9. GWN feedback
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Please send us your feedback[91] and help make the GWN better.

 91. [email protected]

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
10. GWN subscription information
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D

To subscribe to the Gentoo Weekly Newsletter, send a blank e-mail to
[email protected].

To unsubscribe to the Gentoo Weekly Newsletter, send a blank e-mail to
[email protected] from the e-mail address you are
subscribed under.

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
11. Other languages
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

The Gentoo Weekly Newsletter is also available in the following languages=
:

 * Danish[92]
 * Dutch[93]
 * English[94]
 * German[95]
 * French[96]
 * Korean[97]
 * Japanese[98]
 * Italian[99]
 * Polish[100]
 * Portuguese (Brazil)[101]
 * Portuguese (Portugal)[102]
 * Russian[103]
 * Spanish[104]
 * Turkish[105]
 92. http://www.gentoo.org/news/da/gwn/gwn.xml
 93. http://www.gentoo.org/news/nl/gwn/gwn.xml
 94. http://www.gentoo.org/news/en/gwn/gwn.xml
 95. http://www.gentoo.org/news/de/gwn/gwn.xml
 96. http://www.gentoo.org/news/fr/gwn/gwn.xml
 97. http://www.gentoo.org/news/ko/gwn/gwn.xml
 98. http://www.gentoo.org/news/ja/gwn/gwn.xml
 99. http://www.gentoo.org/news/it/gwn/gwn.xml
 100. http://www.gentoo.org/news/pl/gwn/gwn.xml
 101. http://www.gentoo.org/news/pt_br/gwn/gwn.xml
 102. http://www.gentoo.org/news/pt/gwn/gwn.xml
 103. http://www.gentoo.org/news/ru/gwn/gwn.xml
 104. http://www.gentoo.org/news/es/gwn/gwn.xml
 105. http://www.gentoo.org/news/tr/gwn/gwn.xml


Ulrich Plate <[email protected]> - Editor
Patrick Lauer <[email protected]> - Author
Christel Dahlskjaer <[email protected]> - Author
Tobias Scherbaum <[email protected]> - Author
Mark Kowarsky <[email protected]> - Author
Markus Ullmann <[email protected]> - Author
Steve Dibb <[email protected]> - Author
Lucas Chiesa <[email protected]> - Author
Lars Weiler <[email protected]> - Author

--=20
[email protected] mailing list