Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 117377 - app-doc/NaturalDocs-1.22-r1 with world-writeable files and directories
Summary: app-doc/NaturalDocs-1.22-r1 with world-writeable files and directories
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Default Configs (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
: 208187 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-01-01 12:30 UTC by Denilson Sá Maia
Modified: 2008-06-07 13:13 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Denilson Sá Maia 2006-01-01 12:30:03 UTC
Lots of files (if not all files) and directories are installed with 777 or 666 permissions.

How to reproduce:
emerge -av =app-doc/NaturalDocs-1.22-r1
ls -lR /usr/share/NaturalDocs/

Documentation, however, is installed correctly: ls -lR /usr/share/doc/NaturalDocs-1.22-r1/

Tip: Why not use "doins -r" instead of "cp -a" in ebuild?
Comment 1 Josh Glover (RETIRED) gentoo-dev 2006-01-25 21:06:45 UTC
Marking as a duplicate because I will make sure this is fixed in the new ebuild for the latest version, 1.35. Thanks!

*** This bug has been marked as a duplicate of 79212 ***
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2008-01-30 21:54:44 UTC
*** Bug 208187 has been marked as a duplicate of this bug. ***
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2008-01-30 21:59:19 UTC
why's the fixed version not stable? Also, most of the keywords went MIA for unknown reason.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-10 14:39:43 UTC
Josh is 1.35 ready for stable marking?
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-02-12 00:20:12 UTC
It's in the tree for a year.

Arches, please test and mark stable:
=app-doc/NaturalDocs-1.35
Target keywords : "amd64 ppc release x86"
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2008-02-12 07:23:28 UTC
x86 stable
Comment 7 Tobias Scherbaum (RETIRED) gentoo-dev 2008-02-16 18:28:49 UTC
(In reply to comment #5)
> It's in the tree for a year.
> 
> Arches, please test and mark stable:
> =app-doc/NaturalDocs-1.35
> Target keywords : "amd64 ppc release x86"
> 

Keywords for amd64/ppc have been dropped about for $whatever reason ... added ~ppc back to 1.35, will do the stable keyword in a couple of days ...
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2008-02-17 08:19:24 UTC
amd64 stable, updated Status
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2008-02-19 17:15:50 UTC
ppc stable
Comment 10 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-02-19 20:08:37 UTC
It's a local DoS, and with a sane partition scheme (ie not everything under /) it shouldn't be too annoying... I vote NO.
Comment 11 Robert Buchholz (RETIRED) gentoo-dev 2008-02-19 23:55:19 UTC
No, closing.
Comment 12 Peter Volkov (RETIRED) gentoo-dev 2008-02-23 18:03:34 UTC
Fixed in release snapshot.