Language Selection

English French German Italian Portuguese Spanish

Gentoo Infrastructure Press Release

Filed under
Gentoo
Security

On August 7, 2007, bannedit reported bug 187971 regarding a possible command injection vulnerability within http://packages.gentoo.org. The Infrastructure team verified the vulnerability and the server was immediately taken down to prevent further exploitation and to allow for forensic analysis.

The server hosted the following sites and services:

archives.gentoo.org
packagestest.gentoo.org
scripts.gentoo.org
archivestest.gentoo.org
kiss.gentoo.org
packages.gentoo.org
stats.gentoo.org
survey.gentoo.org

While no ETA is currently available, the affected sites and services will be restored. The affected server will be rebuilt while the packages.gentoo.org service's source undergoes a full security audit prior to being restored. The tree and all other services were unaffected.




More in Tux Machines

Turning Windows users into Linux users with MakuluLinux Aero

Slick, sleek, and fast and very Windows-like ... this is a distro that could get your users on the path of OS righteousness Read more

Open Source Education Begins at an Early Age

Open source software (OSS) is becoming a standard in the technology market, and much of today’s youth will find themselves using open source in their future educational and professional endeavors. But to do so, this younger generation will first need to develop the skills that will allow them to build, create and explore OSS technology effectively down the road. This calls for education in open source. Read more

Debian-Based OpenMediaVault 2.1 NAS Solution Adds WiFi and VLAN Support

Volker Theile, project leader of the Debian-based OpenMediaVault NAS (Network-attached Storage) distribution, was more than happy to inform us about the immediate availability for download of OpenMediaVault 2.1. Read more

Arch Linux 2015.07.01 Is Now Available for Download

Being July 1 and all that, that time has come for a new Arch Linux build to surface the Web. Arch Linux 2015.07.01 has been released earlier, and you can download it right now! Read more