public inbox for gnats-announce@sourceware.org
 help / color / mirror / Atom feed
From: Chad Walstrom <chewie@wookimus.net>
To: info-gnats@gnu.org
Subject: Alpha Release 4.1.999
Date: Mon, 24 Sep 2007 14:25:00 -0000	[thread overview]
Message-ID: <20070924140955.C9D5E3C03B@skuld.wookimus.net> (raw)

An alpha release of GNATS has been uploaded to
ftp://alpha.gnu.org/gnu/gnats.  The GNATS team is working on releasing
4.2 and would like your help ironing out the bugs.

From the NEWS file:

GNATS 4.1.999 (Pre-release-candidate), September 2007
=====================================================
Version 4.1.999 is an alpha release that contains many bug-fixes
release and copyright license upgrade to GNU General Public License v3
and GNU Library General Public Library v3.  It includes the
vulnerabilities fixes intended to be released in August 2005.

A Common Vulnerabilities and Exposures candidate [CAN-2005-2180] was
reported for a local security exploit over the misuse of setuid
binaries for manipulating local databases.  The Makefiles have been
altered to discontinue using the setuid bit.

The suggested manner in which to use a local database is to use an
unprivileged user in combination with sudo, or to create a dedicated
filesystem group to which you add your "responsible" team members.
Alternatively, you could operate exclusively through the network
interface.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2180

Since GNATS 4.0.0, there has been trouble trying to build the software
on Solaris machines.  This has now been fixed.

-- 
Chad Walstrom <chewie@wookimus.net>           http://www.wookimus.net/
           assert(expired(knowledge)); /* core dump */


_______________________________________________
Info-gnats mailing list
Info-gnats@gnu.org
http://lists.gnu.org/mailman/listinfo/info-gnats

                 reply	other threads:[~2007-09-24 14:25 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070924140955.C9D5E3C03B@skuld.wookimus.net \
    --to=chewie@wookimus.net \
    --cc=info-gnats@gnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).