Am Sonntag, 9. Dezember 2018, 11:35:16 CET schrieb Philip Webb: > 181208 Marc Joliet wrote: > > This is mentioned in the emerge output when installing imagemagick. > > > > From the 7.0.8.14 ebuild : > > elog "For security reasons, a policy.xml file was installed in > > /etc/ImageMagick-7" > > elog "which will prevent the usage of the following coders by default:" > > elog "" > > elog " - PS" > > elog " - PS2" > > elog " - PS3" > > elog " - EPS" > > elog " - PDF" > > elog " - XPS" > > What exactly are the "security reasons" ? > Do they apply to a single-user system ? -- if not, > why is the restrictive version of the policy file installed by default > rather than a warning at the end of the emerge output ?
Good question. Checking the git log, the change was mode over two commits: https://gitweb.gentoo.org/repo/gentoo.git/commit/? id=02765dfc333e578af9e3fd525fc0067dc47d6528 https://gitweb.gentoo.org/repo/gentoo.git/commit/? id=df7afbda6b12a68578833225e694cee011b20342 The commit messages point to https://www.kb.cert.org/vuls/id/332928/ and https://bugs.gentoo.org/664236, which basically explain in more detail what Mick already summarized yesterday. -- Marc Joliet -- "People who think they know everything really annoy those of us who know we don't" - Bjarne Stroustrup
signature.asc
Description: This is a digitally signed message part.