1 |
181209 Marc Joliet wrote: |
2 |
> Am Sonntag, 9. Dezember 2018, 11:35:16 CET schrieb Philip Webb: |
3 |
>> What exactly are the "security reasons" ? |
4 |
>> Do they apply to a single-user system ? -- if not, |
5 |
>> why is the restrictive version of the policy file installed by default |
6 |
>> rather than a warning at the end of the emerge output ? |
7 |
> Good question. Checking the git log, the change was mode over two commits: |
8 |
> https://gitweb.gentoo.org/repo/gentoo.git/commit/? |
9 |
> id=02765dfc333e578af9e3fd525fc0067dc47d6528 |
10 |
> https://gitweb.gentoo.org/repo/gentoo.git/commit/? |
11 |
> id=df7afbda6b12a68578833225e694cee011b20342 |
12 |
> The commit messages point to https://www.kb.cert.org/vuls/id/332928/ |
13 |
> and https://bugs.gentoo.org/664236, |
14 |
> which basically explain in more detail what Mick summarized yesterday. |
15 |
|
16 |
It looks to me like an over-reaction to a fairly unlikely exploit. |
17 |
You are protected if you don't download images from untrusted sites |
18 |
or if you don't run Ghostscript as root (who would ? ). |
19 |
|
20 |
It's true that you can use 'img2pdf' instead, which is perhaps the solution. |
21 |
|
22 |
-- |
23 |
========================,,============================================ |
24 |
SUPPORT ___________//___, Philip Webb |
25 |
ELECTRIC /] [] [] [] [] []| Cities Centre, University of Toronto |
26 |
TRANSIT `-O----------O---' purslowatchassdotutorontodotca |