Summary: | <dev-vcs/gitolite-3.5.3.1: world writable files for fresh installs | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | alex_y_xu, idl0r |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1046227 | ||
Whiteboard: | B3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2013-12-24 12:02:09 UTC
I haven't used 3.x so far but I think it should be ok to stabilize 3.5.3.1. I don't think this applies to us, since the only 3.x version in tree is ~. Additional information: https://github.com/sitaramc/gitolite/commit/3dad4f8e3214d6ab5f71823019a624fa48b055a3 This was fixed when https://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/dev-vcs/gitolite/gitolite-3.5.3.1.ebuild?hideattic=0&view=log hit the tree. @ Security: Please vote! Vulnerable code is not present in 2.3.1. |