Summary: | <sys-process/fcron-3.0.5-r2: symlink attack (CVE-2010-0792) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Stefan Behte (RETIRED) <craig> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | cron-bugs+disabled, flameeyes, gokdenizk, wschlich |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://fcron.free.fr/ | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Stefan Behte (RETIRED)
![]() ![]() Security, 3.0.5 is in tree now. Only bad note on that is that it depends on a newly-added pambase, but since I only changed the system-services stack it should be fine to go stable as it is even right now. Thanks! 3.0.5-r1 is the stable candidate if security wants a new stable. Arches, please test and mark stable: =sys-process/fcron-3.0.5-r2 Target keywords : "amd64 hppa ppc sparc x86" x86 stable this deps a non-stable version of pambase for most arches. advice? Stable for HPPA. amd64 stable sparc stable ppc done; closing as last arch Reopening, this is a security bug. GLSA vote: yes YES too, request filed. 3.0.5-r2 is the oldest available version in the tree. Is there still a need for a GLSA ? Yes. This issue was resolved and addressed in GLSA 201311-16 at http://security.gentoo.org/glsa/glsa-201311-16.xml by GLSA coordinator Sergey Popov (pinkbyte). |