|Summary:||dev-util/spe installs world writable files|
|Product:||Gentoo Security||Reporter:||Bryan Østergaard (RETIRED) <kloeri>|
|Component:||Vulnerabilities||Assignee:||Gentoo Security <security>|
|Whiteboard:||B2 [glsa] jaervosz|
|Package list:||Runtime testing required:||---|
Description Bryan Østergaard (RETIRED) 2005-10-08 14:25:16 UTC
Due to upstream packaging all files are world writable. I'm mailing upstream about this + fixing our ebuilds (both stable and testing) right now.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) 2005-10-08 22:21:03 UTC
This one is ready for GLSA decision.
Comment 2 Thierry Carrez (RETIRED) 2005-10-09 09:36:24 UTC
I think it's worth one. World writeable executables are bad.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) 2005-10-11 14:00:39 UTC
Let's have a GLSA.
Comment 4 Bryan Østergaard (RETIRED) 2005-10-11 17:30:58 UTC
Fixed in 0.7.5c-r1. If x86 team wants 0.5.x fixed instead I can do that but I'd prefer stabling 0.7.5c-r1 as 0.5.x has a number of other bugs and should be removed imo.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) 2005-10-11 22:18:37 UTC
x86 please test and mark stable.
Comment 6 Mark Loeser (RETIRED) 2005-10-11 23:01:53 UTC
We can't mark it stable until this problem is resolved: dev-util/spe/spe-0.7.5c-r1.ebuild: x86(default-linux/x86/2005.0) ['>=dev-python/wxpython-18.104.22.168']
Comment 7 Thierry Carrez (RETIRED) 2005-10-12 02:33:58 UTC
Maybe simpler to bump 0.5.x with the fix ?
Comment 8 Bryan Østergaard (RETIRED) 2005-10-12 16:38:08 UTC
wxpython-2.6* should be marked stable later tonight. I still prefer stabling spe-0.7* and removing the troublesome 0.5* versions.
Comment 9 Mark Loeser (RETIRED) 2005-10-13 22:26:04 UTC
wxpython is still not stable. Which version should be marked stable? I can test both packages and mark them both.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) 2005-10-13 22:38:11 UTC
afaik only 0.7.5c-r1 is fixed.
Comment 11 Thierry Carrez (RETIRED) 2005-10-14 00:29:49 UTC
I think he was looking for the wxpython version to mark stable. No clue, waiting for kloeri.
Comment 12 Mark Loeser (RETIRED) 2005-10-14 14:32:21 UTC
(In reply to comment #11) > I think he was looking for the wxpython version to mark stable. No clue, waiting > for kloeri. Yea, I was asking about the wxpython version. Sorry for not being clear.
Comment 13 Bryan Østergaard (RETIRED) 2005-10-14 14:43:34 UTC
I just added 0.5.1f-r1 to the tree as I don't want to wait for wxpython-2.6 to go stable any longer.
Comment 14 Mark Loeser (RETIRED) 2005-10-14 15:46:04 UTC
Done on x86, thanks kloeri.
Comment 15 Thierry Carrez (RETIRED) 2005-10-15 03:01:47 UTC