net-analyzer/pnp4nagios: new revision with a better fix for CVE-2012-3457.
authorMichael Orlitzky <mjo@gentoo.org>
Thu, 2 Nov 2017 17:08:14 +0000 (13:08 -0400)
committerMichael Orlitzky <mjo@gentoo.org>
Sat, 4 Nov 2017 23:37:20 +0000 (19:37 -0400)
commit184ae2c637ba60cd8f65d33c9098a2f4a079b4dc
tree0fb6652493df8fad58409b7a4c9e950e7e553c3a
parent8a6c86311831919c79c94f0b4744e05691fe5045
net-analyzer/pnp4nagios: new revision with a better fix for CVE-2012-3457.

In CVE-2012-3457, it was reported that one particular file should not
be world-readable. To fix that, our ebuild made all of /etc/pnp
unreadable; that made other permissions issues difficult to work
around. This r2 sets o-rwx only on /etc/pnp/process_perfdata.cfg.

Bug: https://bugs.gentoo.org/430358
Package-Manager: Portage-2.3.8, Repoman-2.3.3
net-analyzer/pnp4nagios/pnp4nagios-0.6.26-r2.ebuild [moved from net-analyzer/pnp4nagios/pnp4nagios-0.6.26-r1.ebuild with 84% similarity]