Summary: | x11-misc/xnview: insecure rpath | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Tavis Ormandy (RETIRED) <taviso> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | desktop-misc |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3? [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 81745 |
Description
Tavis Ormandy (RETIRED)
![]() Got reply from Pierre-e Gougelet (author of Xnview):
--------
> Is it possible for us to
> modify the RPATH while installing the package - wouldn't it violate the
> licence?
No
--------
Version 1.70-r1 which fixes this bug is in portage. arches, pls test and mark stable. x86 done. 1.70-r1 stable. mhhh ok, seems this ready for glsa vote (is B3 ok here, anyways?). Also, as nelchael pointed out, ppc is probably not vulnerable, but i still want them to take a look while we continue the glsa process without waiting for them to stable. vote YES, pretty serious. We have a draft, lets have a GLSA, I vote yes. GLSA 200512-18 |