1 |
Am Sonntag, 9. Dezember 2018, 11:35:16 CET schrieb Philip Webb: |
2 |
> 181208 Marc Joliet wrote: |
3 |
> > This is mentioned in the emerge output when installing imagemagick. |
4 |
> > |
5 |
> > From the 7.0.8.14 ebuild : |
6 |
> > elog "For security reasons, a policy.xml file was installed in |
7 |
> > /etc/ImageMagick-7" |
8 |
> > elog "which will prevent the usage of the following coders by default:" |
9 |
> > elog "" |
10 |
> > elog " - PS" |
11 |
> > elog " - PS2" |
12 |
> > elog " - PS3" |
13 |
> > elog " - EPS" |
14 |
> > elog " - PDF" |
15 |
> > elog " - XPS" |
16 |
> |
17 |
> What exactly are the "security reasons" ? |
18 |
> Do they apply to a single-user system ? -- if not, |
19 |
> why is the restrictive version of the policy file installed by default |
20 |
> rather than a warning at the end of the emerge output ? |
21 |
|
22 |
Good question. Checking the git log, the change was mode over two commits: |
23 |
|
24 |
https://gitweb.gentoo.org/repo/gentoo.git/commit/? |
25 |
id=02765dfc333e578af9e3fd525fc0067dc47d6528 |
26 |
https://gitweb.gentoo.org/repo/gentoo.git/commit/? |
27 |
id=df7afbda6b12a68578833225e694cee011b20342 |
28 |
|
29 |
The commit messages point to https://www.kb.cert.org/vuls/id/332928/ and |
30 |
https://bugs.gentoo.org/664236, which basically explain in more detail what |
31 |
Mick already summarized yesterday. |
32 |
|
33 |
-- |
34 |
Marc Joliet |
35 |
-- |
36 |
"People who think they know everything really annoy those of us who know we |
37 |
don't" - Bjarne Stroustrup |