Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 618248 - x11-terms/rxvt-unicode - ship hardening patch
Summary: x11-terms/rxvt-unicode - ship hardening patch
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Jeroen Roovers (RETIRED)
URL: http://seclists.org/oss-sec/2017/q2/185
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-11 19:58 UTC by Jason A. Donenfeld
Modified: 2017-05-19 18:38 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
rxvt-unicode-defense-in-depth-fix.patch (rxvt-unicode-defense-in-depth-fix.patch,447 bytes, patch)
2017-05-11 19:58 UTC, Jason A. Donenfeld
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Jason A. Donenfeld gentoo-dev 2017-05-11 19:58:48 UTC
Created attachment 472374 [details, diff]
rxvt-unicode-defense-in-depth-fix.patch

As discussed via personal email and on oss-sec, the attached patch should be applied to the rxvt-unicode patch.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2017-05-12 06:53:03 UTC
This is not a security bug.
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2017-05-12 06:59:23 UTC
(In reply to Jason A. Donenfeld from comment #0)
> Created attachment 472374 [details, diff] [details, diff]
> rxvt-unicode-defense-in-depth-fix.patch

Jason, has upstream accepted the patch yet?

> As discussed via personal email and on oss-sec, the attached patch should be
> applied to the rxvt-unicode patch.

Well, you asked me to apply the patch and I asked what upstream thinks of it. That's not a discussion. The last thing you said about it was:

   "rxvt-unicode isn't vulnerable, but the patch I sent you is worth
    applying as a defense-in-depth measure. I've sent it upstream and am
    awaiting their response."

I am awaiting their response, too. No related commits yet, nothing on the mailing list (where did you send that e-mail to?), no updates in the Changes file.
Comment 3 Jason A. Donenfeld gentoo-dev 2017-05-12 08:06:49 UTC
Okay, no problem. I'll poke upstream again and also add them to this bug report.