Re: libpng-1.0.60, 1.2.50, 1.4.12, 1.5.12, and 1.6.0beta26 released to fix vulnerability
[email protected] Thu, 12 Jul 2012 14:36:21 +0000 (UTC)
| Newsgroups | gmane.comp.graphics.png.announce |
|---|---|
| Message-ID | <1742936085.1219682.1342103781236.JavaMail.root__31020.3052861199$1342103822$gmane$org@sz0023a.westchester.pa.mail.comcast.net> |
----- Greg Roelofs <[email protected]> wrote: > Glenn Randers-Pehrson <[email protected]> wrote: > > > The CVE-2012-3386 vulnerability only affects users when they > > run "make distcheck" and have failed to set a umask that prevents > > writing publicly-writable files. > > umask has no effect on chmod; all users who run "make distcheck" are > affected (though only insofar as they make use of the freshly unpacked > binaries or other files in $(distdir) in some way). That is correct. I misread something in the discussion of the vulnerability. I don't know how to change the CHANGES files without making another release, but you can say something in libpng.html to the effect that the statement about umask in the CHANGES should be ignored and that the vulnerability exists even when the user has properly set up a "secure" umask. G ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/