View previous topic :: View next topic |
Author |
Message |
Lupin_the_3rd Apprentice
Joined: 03 Apr 2005 Posts: 168
|
Posted: Sat Aug 18, 2007 4:31 am Post subject: packages.gentoo.org |
|
|
Where did it go? It has been down for many days now? _________________ Compaq XP1000 Alpha EV67 667Mhz w/ 2GB ECC
32bit PCI: ATI Radeon 9100 (DRI works!)
32bit PCI: Generic Firewire 400 card
64bit PCI: BCM5703 Gig-E (Compaq NC7771)
64bit PCI: Sil3124 SATA w/ mdadm RAID1 (pair of WD VelociRaptors) |
|
Back to top |
|
|
jfb3 Apprentice
Joined: 01 Feb 2003 Posts: 242
|
Posted: Sat Aug 18, 2007 4:51 am Post subject: |
|
|
To quote from www.gentoo.org:
Code: | On August 7, 2007, bannedit reported bug 187971 regarding a possible command injection vulnerability within http://packages.gentoo.org. The Infrastructure team verified the vulnerability and the server was immediately taken down to prevent further exploitation and to allow for forensic analysis.
The server hosted the following sites and services:
* archives.gentoo.org
* packagestest.gentoo.org
* scripts.gentoo.org
* archivestest.gentoo.org
* kiss.gentoo.org
* packages.gentoo.org
* stats.gentoo.org
* survey.gentoo.org
While no ETA is currently available, the affected sites and services will be restored. The affected server will be rebuilt while the packages.gentoo.org service's source undergoes a full security audit prior to being restored. The tree and all other services were unaffected.
|
|
|
Back to top |
|
|
desultory Bodhisattva
Joined: 04 Nov 2005 Posts: 9410
|
Posted: Sat Aug 18, 2007 5:05 am Post subject: |
|
|
Moved from Installing Gentoo to Duplicate Threads, as this is a duplicate of topic "packages.gentoo.org". |
|
Back to top |
|
|
|