Gentoo Archives: gentoo-user

From: Philip Webb <purslow@××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] ...I not allowed to make pdfs from images??????
Date: Sun, 09 Dec 2018 15:46:48
Message-Id: 20181209154639.GE1924@ca.inter.net
In Reply to: Re: [gentoo-user] ...I not allowed to make pdfs from images?????? by Marc Joliet
1 181209 Marc Joliet wrote:
2 > Am Sonntag, 9. Dezember 2018, 11:35:16 CET schrieb Philip Webb:
3 >> What exactly are the "security reasons" ?
4 >> Do they apply to a single-user system ? -- if not,
5 >> why is the restrictive version of the policy file installed by default
6 >> rather than a warning at the end of the emerge output ?
7 > Good question. Checking the git log, the change was mode over two commits:
8 > https://gitweb.gentoo.org/repo/gentoo.git/commit/?
9 > id=02765dfc333e578af9e3fd525fc0067dc47d6528
10 > https://gitweb.gentoo.org/repo/gentoo.git/commit/?
11 > id=df7afbda6b12a68578833225e694cee011b20342
12 > The commit messages point to https://www.kb.cert.org/vuls/id/332928/
13 > and https://bugs.gentoo.org/664236,
14 > which basically explain in more detail what Mick summarized yesterday.
15
16 It looks to me like an over-reaction to a fairly unlikely exploit.
17 You are protected if you don't download images from untrusted sites
18 or if you don't run Ghostscript as root (who would ? ).
19
20 It's true that you can use 'img2pdf' instead, which is perhaps the solution.
21
22 --
23 ========================,,============================================
24 SUPPORT ___________//___, Philip Webb
25 ELECTRIC /] [] [] [] [] []| Cities Centre, University of Toronto
26 TRANSIT `-O----------O---' purslowatchassdotutorontodotca

Replies

Subject Author
Re: [gentoo-user] ...I not allowed to make pdfs from images?????? Arve Barsnes <arve.barsnes@×××××.com>
Re: [gentoo-user] ...I not allowed to make pdfs from images?????? Marc Joliet <marcec@×××.de>