From mboxrd@z Thu Jan 1 00:00:00 1970 From: Marius Bakke Subject: Re: [PATCH] gnu: ntfs-3g: Fix CVE-2017-0358. Date: Thu, 09 Feb 2017 23:39:42 +0100 Message-ID: <878tpft2dt.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> References: <87bmuboxqf.fsf@openmailbox.org> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:47382) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cbxNX-0000nY-LL for guix-devel@gnu.org; Thu, 09 Feb 2017 17:39:52 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cbxNS-0000lr-Ot for guix-devel@gnu.org; Thu, 09 Feb 2017 17:39:51 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:44297) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cbxNS-0000ld-EC for guix-devel@gnu.org; Thu, 09 Feb 2017 17:39:46 -0500 In-Reply-To: <87bmuboxqf.fsf@openmailbox.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Kei Kebreau , guix-devel@gnu.org --=-=-= Content-Type: text/plain Kei Kebreau writes: > Reviewers, how does this patch look to you? AFAIU from CVE-2017-0358, ntfs-3g is only vulnerable when installed setuid root, which is not the case on guix. FWIW Debian do not carry this patch, but have fixed the CVE according to the changelog. So I doubt this patch is necessary. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEu7At3yzq9qgNHeZDoqBt8qM6VPoFAlic764ACgkQoqBt8qM6 VPrgQAf/Qw3iA3hT7T4lWZQllw6OIOSFYXe3KbJzfE4eaApMdnqDVzWxzw1vd8xK ds0FafTkIR/8vCs6DM6Jde3cMqj5dKcr2X8hD314Mfd+3YC+VmPkVNgvRwxTEq8m y7CyjcqtOF+iZ1Uf9wUm0nRP//BGN4PXhxShewS+KD0Q9/IDZHrP3HUmJzwFYQlN S5wVLby/xiy+sG/DmO12vjjclPPtcAM0aNoA5+MnAVrVKF6SgpK0NK307qbhAhpz E0u9g0WyCzqJtkrneUSEiE5GcJg/e5m5jxIcEN57hrNL5ZoaOcrZKVGYY8Kzo5kP 1eZFe+jO80yieOnhZiOnvIicyeLe4A== =PtCT -----END PGP SIGNATURE----- --=-=-=--