net-misc/peervpn: 0.044-r2 revbump for bug 602550
authorZac Medico <zmedico@gentoo.org>
Tue, 13 Dec 2016 17:50:33 +0000 (09:50 -0800)
committerZac Medico <zmedico@gentoo.org>
Tue, 13 Dec 2016 17:55:11 +0000 (09:55 -0800)
commitf36646ec19b50b45cbf6def47e8e34ac2237b3c8
tree6ac5522e5f996d2f4b4e32241721ecc930c4464e
parent057395a1d76f70fd15102c2a0365799f3500e863
net-misc/peervpn: 0.044-r2 revbump for bug 602550

Remove the chown call from the openrc init script start_post function,
in order to prevent privilege escalation attacks. It is unsafe to call
chown in a directory that is not owned by root, since the target file
could be a hardlink to a root-owned file.

X-Gentoo-bug: 602550
X-Gentoo-bug-url: https://bugs.gentoo.org/show_bug.cgi?id=602550

Package-Manager: portage-2.3.3
net-misc/peervpn/files/peervpn.initd
net-misc/peervpn/files/peervpn.logrotated
net-misc/peervpn/peervpn-0.044-r2.ebuild [moved from net-misc/peervpn/peervpn-0.044-r1.ebuild with 96% similarity]