Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 186177 - gnome-extra/gnome-screensaver leaky setgid
Summary: gnome-extra/gnome-screensaver leaky setgid
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-07-22 02:52 UTC by Saleem Abdulrasool (RETIRED)
Modified: 2007-07-29 22:21 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Saleem Abdulrasool (RETIRED) gentoo-dev 2007-07-22 02:52:48 UTC
gnome-screensaver installed +s when u+s should have been used.  This only effects people who build it -pam.

Reproducible: Always

Steps to Reproduce:
Comment 1 Saleem Abdulrasool (RETIRED) gentoo-dev 2007-07-22 02:53:13 UTC
btw, this was brought to my attention by taviso.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-07-22 07:54:14 UTC
gnome please fix this one.
Comment 3 Gilles Dartiguelongue (RETIRED) gentoo-dev 2007-07-22 19:35:35 UTC
compnerd did it :)
Comment 4 Gilles Dartiguelongue (RETIRED) gentoo-dev 2007-07-22 19:37:22 UTC
oops, that was for security herd.
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-22 19:48:22 UTC
hmmm, did you do a stable bump? anyway, not sure which versions are affected or not in the end, so please specify which version we should ask for going stable.
Comment 6 Saleem Abdulrasool (RETIRED) gentoo-dev 2007-07-25 01:58:22 UTC
yes, they were stable bumps -- all versions were effected.
Comment 7 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-26 11:38:26 UTC
ok, but for the next security issues please use the normal stabilization process to be sure that our users don't end with a br0ken app when upgrading, either normally or with glsa-check. so, skipping directly to glsa decision. I vote no. 
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-07-26 15:21:51 UTC
I tend to vote NO.
Comment 9 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-07-29 22:21:16 UTC
i vote No too. CLosing, feel free to reopen if you disagree.

@py: i am totally OK with direct stable bumps when the patch is trivial, which is the case here.