Summary: | app-portage/getdelta: root privilege escalation via "chown -R" in pkg_postinst | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Michael Orlitzky <mjo> |
Component: | Auditing | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | Ameretat.Reith, nlissne, patrick, proxy-maint, security-audit, treecleaner |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | ~1 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Michael Orlitzky
![]() Unrestricting and reassigning to security@ per bug #705894 unrestricting per bug 705894 CCing proxied maintainer. Never touched by a maintainer since the git transition and no real changes in the same time. EAPI 5. CCing treecleaner. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b965153d7733fe0a58bdd54a378cd337e76a420c commit b965153d7733fe0a58bdd54a378cd337e76a420c Author: Jakov Smolic <jakov.smolic@sartura.hr> AuthorDate: 2021-08-24 12:38:35 +0000 Commit: David Seifert <soap@gentoo.org> CommitDate: 2021-08-24 12:38:35 +0000 app-portage/getdelta: Remove last-rited package Closes: https://bugs.gentoo.org/371635 Bug: https://bugs.gentoo.org/630814 Signed-off-by: Jakov Smolic <jakov.smolic@sartura.hr> Signed-off-by: David Seifert <soap@gentoo.org> app-portage/getdelta/Manifest | 1 - app-portage/getdelta/files/getdelta-0.7.9.patch | 252 ------------------------ app-portage/getdelta/getdelta-0.7.9-r2.ebuild | 46 ----- app-portage/getdelta/metadata.xml | 8 - profiles/package.mask | 5 - 5 files changed, 312 deletions(-) All done! |