Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 820608 - app-misc/binwalk-2.3.3: stabilization
Summary: app-misc/binwalk-2.3.3: stabilization
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Georgy Yakovlev
URL:
Whiteboard:
Keywords: CC-ARCHES, SECURITY, STABLEREQ
Depends on:
Blocks: 820614
  Show dependency tree
 
Reported: 2021-10-28 16:19 UTC by Georgy Yakovlev
Modified: 2021-10-30 17:24 UTC (History)
1 user (show)

See Also:
Package list:
app-misc/binwalk-2.3.3
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Georgy Yakovlev archtester gentoo-dev 2021-10-28 16:19:48 UTC
version 2.3.3 fixed a security issue 



Prior to Binwalk v2.3.3, extracted archives could create symlinks which point anywhere on the file system, potentially resulting in a directory traversal attack if subsequent extraction utilties blindly follow these symlinks. More generically, Binwalk makes use of many third-party extraction utilties which may have unpatched security issues; Binwalk v2.3.3 and later allows external extraction tools to be run as an unprivileged user using the `run-as` command line option (this requires Binwalk itself to be run with root privileges). Additionally, Binwalk v2.3.3 and later will refuse to perform extraction as root unless `--run-as=root` is specified.



it's a bugfix release, so let's get it stable and drop old versions.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-10-28 19:56:17 UTC
This is a regular stablereq, maintainer should be assigned.
Comment 2 Agostino Sarubbo gentoo-dev 2021-10-29 05:52:33 UTC
amd64 stable
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-10-29 18:30:17 UTC
arm64 done
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-10-29 18:32:28 UTC
ppc64 done
Comment 5 Agostino Sarubbo gentoo-dev 2021-10-30 17:24:25 UTC
x86 stable. Closing.