1 |
On Wed, Jul 14, 2021 at 12:04:34AM +0200, Andreas K. Huettel wrote: |
2 |
> <snip> |
3 |
> > The package was masked due to a miscommunication with the Gentoo |
4 |
> > Security project. |
5 |
> > |
6 |
> > While it is true that the way opentmpfiles is currently implemented |
7 |
> > allows for certain races, from the security point of view, you always |
8 |
> > have to classify the vulnerability in context of your threat model |
9 |
> > because security depends on multiple layers (onion model). |
10 |
> <snip> |
11 |
> |
12 |
> I would like to respectfully point out that this makes |
13 |
> |
14 |
> 1) either the severity assignment of this bug by the Security project as B1 wrong (i.e. it should have been classified "harmless") |
15 |
> |
16 |
|
17 |
The Gentoo model is not perfect and should be overhauled. However, it |
18 |
works for most things and sometimes bugs fall between the cracks. |
19 |
|
20 |
The package shouldn't have been masked either based on a bug that was |
21 |
purposely ignored for many years simply because they want to disband the |
22 |
package now and found a "security reason" to add to the mask. |
23 |
|
24 |
> 2) or the entire classification of severity levels according to the Security project pointless (i.e. you can't base any actions on them because a mystery onion needs to be taken into account). |
25 |
> |
26 |
|
27 |
I am not sure if this is sarcasm, but every bug must be considered |
28 |
through the correct aperture. That is, based on your environment, |
29 |
protections in place, defense in depth, and other buzzwords... hence the |
30 |
onion analogy. |
31 |
|
32 |
-Aaron |