Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 444690 - Please mask <app-shells/bash-4.2_p37
Summary: Please mask <app-shells/bash-4.2_p37
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Normal enhancement
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-25 13:48 UTC by Agostino Sarubbo
Modified: 2015-10-20 20:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-11-25 13:48:02 UTC
If you want to keep it/them in the tree, please mask <app-shells/bash-4.2_p37 because of the security bug 431850.
Comment 1 SpanKY gentoo-dev 2012-11-25 17:52:12 UTC
i don't see the point
Comment 2 Agostino Sarubbo gentoo-dev 2012-11-25 18:08:05 UTC
(In reply to comment #1)
> i don't see the point

the point is very very easy. The rule is: the maintainer must remove the vulnerable ebuilds from the tree to avoid users that accidentally could install them.

If it is a particular case, like bash, if you want to keep it in the tree, you need to mask it, to avoid users that accidentally could install them.

What's not clear?
Comment 3 SpanKY gentoo-dev 2013-12-22 23:43:27 UTC
(In reply to Agostino Sarubbo from comment #2)

users don't accidentally install older bash.  even then, anyone relying on `rbash` as a security solution deserves to be owned.

hard rules that don't take into account the realities are stupid rules.

we're not dropping old bash versions.
Comment 4 Sergey Popov (RETIRED) gentoo-dev 2014-03-20 10:16:08 UTC
Even if they are slotted now, they are still vulnerable(and they are stable), so, if users are definitely sure to use them - they can unmask them.

CCing security@ to this discussion
Comment 5 SpanKY gentoo-dev 2015-10-20 20:35:05 UTC
we're not masking them, although it's moot now that the fix is backported