commit:     ced099c9abfde464b5c1ad0dcb2451a8c62c5e56
Author:     Andrew Savchenko <bircoph <AT> gentoo <DOT> org>
AuthorDate: Sat Jul  9 09:19:53 2016 +0000
Commit:     Andrew Savchenko <bircoph <AT> gentoo <DOT> org>
CommitDate: Sat Jul  9 09:23:00 2016 +0000
URL:        https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ced099c9

package.mask: update xcdroast p.mask

Only versions before app-cdr/xcdroast-0.98_alpha16-r2 are
vulnerable to bug 345337.

 profiles/package.mask | 9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)

diff --git a/profiles/package.mask b/profiles/package.mask
index f6dbb68..2506b9a 100644
--- a/profiles/package.mask
+++ b/profiles/package.mask
@@ -30,6 +30,10 @@
 
 #--- END OF EXAMPLES ---
 
+# Andrew Savchenko <birc...@gentoo.org> (09 Jul 2016)
+# Vulnerable due to wrong suid binary permissions (#345337)
+<app-cdr/xcdroast-0.98_alpha16-r2
+
 # Michael Palimaka <kensing...@gentoo.org) (7 Jul 2016)
 # Requires obsolete kde-apps/kate:4. No further upstream development.
 # Masked for removal in 30 days.
@@ -220,11 +224,6 @@ app-portage/epm
 dev-libs/vdk
 
 # Pacho Ramos <pa...@gentoo.org> (12 Jun 2016)
-# Upstream dead for ages, multiple bugs (#345337)
-# Removal in a month.
-app-cdr/xcdroast
-
-# Pacho Ramos <pa...@gentoo.org> (12 Jun 2016)
 # No buildable version in the tree and nobody is taking care
 # of it (#349457). Removal in a month.
 media-tv/dvbstreamer

Reply via email to