<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>162700</bug_id>
          
          <creation_ts>2007-01-18 20:10 0000</creation_ts>
          <short_desc>app-i18n/kurso-de-esperanto-3.0 - world writeable bit on all files</short_desc>
          <delta_ts>2007-02-10 19:43:10 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B3?? [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>quatrox@gmail.com</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>quatrox@gmail.com</who>
            <bug_when>2007-01-18 20:10:28 0000</bug_when>
            <thetext>When I try to emerge app-i18n/kurso-de-esperanto-3.0, I get this notice on all the files:

 * QA Notice: Pre-stripped files found:
 * /var/tmp/portage/app-i18n/kurso-de-esperanto-3.0/image/opt/kurso/bin/kurso3
/var/tmp/portage/app-i18n/kurso-de-esperanto-3.0/image/opt/kurso/lib/libborqt-6.9-qt2.3.so
QA Security Notice:
- /opt/kurso/fonts/Menu_2.xfm will be a world writable file.
- This may or may not be a security problem, most of the time it is one.
- Please double check that kurso-de-esperanto-3.0 really needs a world writeable bit and file bugs accordingly.


Reproducible: Always

Steps to Reproduce:
1. emerge app-i18n/kurso-de-esperanto-3.0</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-01-26 12:08:11 0000</bug_when>
            <thetext>confirmed... the tarball contains indeed world-writeable files, only had a quick look, but it seems that only fonts/html/... seem to be world-writable, not the binary

vapier, you committed this a long while ago, want to fix it?
otherwise we should mask it until there is a maintainer</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2007-01-27 11:48:07 0000</bug_when>
            <thetext>lame, just fix the freaking package

3.0-r1 in portage</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-01-27 19:03:28 0000</bug_when>
            <thetext>unsure about the rating...

security, please vote</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2007-01-27 21:37:07 0000</bug_when>
            <thetext>I vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-01-27 22:47:52 0000</bug_when>
            <thetext>another NO vote.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-10 19:43:10 0000</bug_when>
            <thetext>closing</thetext>
          </long_desc>
      
    </bug>

</bugzilla>