Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 108538

Summary: dev-util/spe installs world writable files
Product: Gentoo Security Reporter: Bryan Østergaard (RETIRED) <kloeri>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: normal CC: marduk
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [glsa] jaervosz
Package list:
Runtime testing required: ---

Description Bryan Østergaard (RETIRED) gentoo-dev 2005-10-08 14:25:16 UTC
Due to upstream packaging all files are world writable. I'm mailing upstream
about this + fixing our ebuilds (both stable and testing) right now.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-08 22:21:03 UTC
This one is ready for GLSA decision.  
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-10-09 09:36:24 UTC
I think it's worth one. World writeable executables are bad.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-11 14:00:39 UTC
Let's have a GLSA. 
Comment 4 Bryan Østergaard (RETIRED) gentoo-dev 2005-10-11 17:30:58 UTC
Fixed in 0.7.5c-r1. If x86 team wants 0.5.x fixed instead I can do that but I'd
prefer stabling 0.7.5c-r1 as 0.5.x has a number of other bugs and should be
removed imo.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-11 22:18:37 UTC
x86 please test and mark stable. 
Comment 6 Mark Loeser (RETIRED) gentoo-dev 2005-10-11 23:01:53 UTC
We can't mark it stable until this problem is resolved:

   dev-util/spe/spe-0.7.5c-r1.ebuild: x86(default-linux/x86/2005.0)
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-10-12 02:33:58 UTC
Maybe simpler to bump 0.5.x with the fix ?
Comment 8 Bryan Østergaard (RETIRED) gentoo-dev 2005-10-12 16:38:08 UTC
wxpython-2.6* should be marked stable later tonight. I still prefer stabling
spe-0.7* and removing the troublesome 0.5* versions.
Comment 9 Mark Loeser (RETIRED) gentoo-dev 2005-10-13 22:26:04 UTC
wxpython is still not stable.  Which version should be marked stable?  I can
test both packages and mark them both.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-13 22:38:11 UTC
afaik only 0.7.5c-r1 is fixed. 
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-10-14 00:29:49 UTC
I think he was looking for the wxpython version to mark stable. No clue, waiting
for kloeri.
Comment 12 Mark Loeser (RETIRED) gentoo-dev 2005-10-14 14:32:21 UTC
(In reply to comment #11)
> I think he was looking for the wxpython version to mark stable. No clue, waiting
> for kloeri.

Yea, I was asking about the wxpython version.  Sorry for not being clear.
Comment 13 Bryan Østergaard (RETIRED) gentoo-dev 2005-10-14 14:43:34 UTC
I just added 0.5.1f-r1 to the tree as I don't want to wait for wxpython-2.6 to
go stable any longer.
Comment 14 Mark Loeser (RETIRED) gentoo-dev 2005-10-14 15:46:04 UTC
Done on x86, thanks kloeri.
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2005-10-15 03:01:47 UTC
GLSA 200510-13
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2006-01-12 02:50:22 UTC
*** Bug 108494 has been marked as a duplicate of this bug. ***