Gentoo Archives: gentoo-commits

From: Mart Raudsepp <leio@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] repo/gentoo:master commit in: profiles/
Date: Fri, 23 Feb 2018 05:34:09
Message-Id: 1519363978.a880818f9d0e1f8ae97cd3f94208a48709c032b5.leio@gentoo
1 commit: a880818f9d0e1f8ae97cd3f94208a48709c032b5
2 Author: Mart Raudsepp <leio <AT> gentoo <DOT> org>
3 AuthorDate: Fri Feb 23 05:32:58 2018 +0000
4 Commit: Mart Raudsepp <leio <AT> gentoo <DOT> org>
5 CommitDate: Fri Feb 23 05:32:58 2018 +0000
6 URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a880818f
7
8 profiles: p.mask net-lib/webkit-gtk SLOT=2 and SLOT=3 for security
9
10 Bug: https://bugs.gentoo.org/577068
11
12 profiles/package.mask | 10 ++++++++++
13 1 file changed, 10 insertions(+)
14
15 diff --git a/profiles/package.mask b/profiles/package.mask
16 index b434750712e..0d29da6bc95 100644
17 --- a/profiles/package.mask
18 +++ b/profiles/package.mask
19 @@ -29,6 +29,16 @@
20
21 #--- END OF EXAMPLES ---
22
23 +# Mart Raudsepp <leio@g.o> (23 Feb 2018)
24 +# Old net-libs/webkit-gtk SLOTs have hundreds of known security issues.
25 +# Use the security safe net-libs webkit-gtk SLOT=4 instead via
26 +# libraries and applications ported to gtk3 and webkit2gtk API.
27 +# Masked for removal in 30 days. Bug #577068.
28 +# Please keep this package.mask entry until at least 25th May 2018 for
29 +# extra notification of the security vulnerabilities.
30 +net-libs/webkit-gtk:2
31 +net-libs/webkit-gtk:3
32 +
33 # Mart Raudsepp <leio@g.o> (23 Feb 2018)
34 # Older versions of GnuCash use security vulnerable old webkit-gtk slot.
35 # Use gnucash-2.7.4 or newer instead, but pay attention to the news item: