Summary: | <app-text/texlive-2015: insecure use of /tmp in mktexlsr | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | aballier, tex |
Priority: | Low | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1181167 | ||
Whiteboard: | B4 [noglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2015-01-13 08:48:03 UTC
fixed in kpathsea-6.2.1_p20150521-r2 this *cannot* go stable yet; we'll get the whole texlive 2015 stable together with bug #432144 CVE assignment: http://seclists.org/oss-sec/2015/q3/250 Maintainer(s), please drop the vulnerable version(s). Cleanup PR: https://github.com/gentoo/gentoo/pull/4853 Ping. PR has QA issues. For more info: https://github.com/gentoo/gentoo/pull/4853 Security Team Padawan ChrisADR Tree is clean for this package. texlive-core is not, but that is in bug #432144. GLSA Vote: No |