GNU bug report logs -
#37744
Insecure permissions on /var/guix/profiles/per-user (CVE-2019-18192)
Previous Next
Reported by: Ludovic Courtès <ludo <at> gnu.org>
Date: Mon, 14 Oct 2019 07:48:02 UTC
Severity: important
Tags: security
Done: Ludovic Courtès <ludo <at> gnu.org>
Bug is archived. No further changes may be made.
Full log
View this message in rfc822 format
[Message part 1 (text/plain, inline)]
Ludo',
Ludovic Courtès 写道:
> See https://issues.guix.gnu.org/issue/37744
Will this be automatically linkified?
> This issue was initially [reported by Michael Orlitzky for
> Nix](https://www.openwall.com/lists/oss-security/2019/10/09/4)
> ([CVE-2019-17365](https://nvd.nist.gov/vuln/detail?vulnId=CVE-2019-17365)).
>
> # Fix
>
> The [fix](https://issues.guix.gnu.org/issue/37744) consists in
> letting
From the Oxford Dictionaries:
1 (consist of) be composed or made up of
(consist in) have as an essential feature
TIL.
> # Upgrading
>
> On multi-user systems, we recommend upgrading the daemon now.
>
> To upgrade the daemon on a “foreign distro”, run something along
> these
Imperialist nitpick: why list the foreigners first? :-)
Anti-imperialist nitpick: reversing the two allows using ‘other
distributions’ instead of ‘foreign’ which always sounds a bit
dismissive to my ears.
End nitpick.
Thank you for taking care of this from start to finish,
T G-R
[signature.asc (application/pgp-signature, inline)]
This bug report was last modified 5 years and 300 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.