Re: libpng-1.0.60, 1.2.50, 1.4.12, 1.5.12, and 1.6.0beta26 released to fix vulnerability

Greg Roelofs <[email protected]> Thu, 12 Jul 2012 01:36:57 -0700
Newsgroups gmane.comp.graphics.png.announce
Message-ID <[email protected]>
Glenn Randers-Pehrson <[email protected]> wrote:

> The CVE-2012-3386 vulnerability only affects users when they
> run "make distcheck" and have failed to set a umask that prevents
> writing publicly-writable files.

umask has no effect on chmod; all users who run "make distcheck" are
affected (though only insofar as they make use of the freshly unpacked
binaries or other files in $(distdir) in some way).

Greg

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/