libgcrypt - CVE-2013-4242

Michael Schwendt mschwendt at gmail.com
Thu Aug 1 08:07:37 UTC 2013


On Thu, 01 Aug 2013 04:21:15 +0200, poma wrote:

> Example 3 - libgcrypt
> - koji:
>   Information for build libgcrypt-1.5.3-1.fc19
>   Tags 	f19-updates
> 
> - admin:
>   libgcrypt-1.5.3-1.fc19 security update
>   Status:	testing
>   Requested: 	stable
>   Pushed: 	False
> 
> 
> Summary:
> - Example 1 - 'koji' is in accordance with 'admin' => updates
> - Example 2 - 'koji' is in accordance with 'admin' => updates-testing
> - Example 3 - 'koji' -> updates isn't in accordance with
>               'admin' -> updates-testing

The "Status" field in bodhi is not the same as the tag in koji.
When bodhi pushes packages, it adjusts the tags in koji,

  bodhi - 2013-07-31 15:52:43
  This update is currently being pushed to the Fedora 19 stable updates repository. 

and creates a temporary inconsistency between what koji tells about
the package (that it's tagged for "stable" already) and what bodhi's
own Status (the previous Test Update) tells. This will be like that
until the updates repo is regenerated, which takes some time.
Topic might be more suitable for the following list:
https://lists.fedoraproject.org/mailman/listinfo/buildsys


More information about the test mailing list