Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
View Bug Activity | Format For Printing | XML | Clone This Bug
From Changelog: bug#14209: Security bug with --restrict-read-only and --restrict-update-only allowed file statting and directory listing outside path. Bug with --restrict option allowed writes outside path. (Reported by Charles Duffy.)
Ccing maintainer
Ccing a possible herd match as mholzer is apparently missing.
in cvs now, 1.0.1 for this security fix only, 1.0.1-r1 for the new acl/attr stuff (has new deps that need keywording across arches).
Thx Robin. Archs, please test and mark 1.0.1 stable... I guess 1.0.1-r1 should be left in ~ for the time being.
sparc stable.
Stable on ppc.
Stable on x86
Ready for GLSA vote
I tend to vote NO.
I tend to vote NO too...
Closing without GLSA, reopen if you disagree.