guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH] gnu: ntfs-3g: Fix CVE-2017-0358.


From: Leo Famulari
Subject: Re: [PATCH] gnu: ntfs-3g: Fix CVE-2017-0358.
Date: Thu, 9 Feb 2017 23:43:46 +0100
User-agent: Mutt/1.7.2 (2016-11-26)

On Thu, Feb 09, 2017 at 11:39:42PM +0100, Marius Bakke wrote:
> Kei Kebreau <address@hidden> writes:
> 
> > Reviewers, how does this patch look to you?
> 
> AFAIU from CVE-2017-0358, ntfs-3g is only vulnerable when installed
> setuid root, which is not the case on guix.
> 
> FWIW Debian do not carry this patch, but have fixed the CVE according to
> the changelog. So I doubt this patch is necessary.

There have been a couple security-related bugs publicized recently that
are only dangerous when the software is installed setuid root.

Although we don't do that by default, system administrators can do it on
GuixSD. I also think that Guix is valuable as a distribution mechanism
of free source code, and we should fix bugs for that use case.

So, I was thinking that we should fix these bugs unless they require
grafting, and then we should fix them in core-updates.

WDYT?

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]