Subject: Re: CVS commit: pkgsrc/archivers/gcpio
To: Lubomir Sedlacik <salo@netbsd.org>
From: Jeremy C. Reed <reed@reedmedia.net>
List: pkgsrc-changes
Date: 03/21/2005 08:23:39
On Sun, 20 Mar 2005, Lubomir Sedlacik wrote:

> Added Files:
> 	pkgsrc/archivers/gcpio/patches: patch-ah
>
> Log Message:
> Security fix for CAN-1999-1572.
>
> "cpio uses a 0 umask when creating files using the -O (archive) or -F
>  options, which creates the files with mode 0666 and allows local users
>  to read or overwrite those files."
>
> Patch inspired by Debian.  Bump PKGREVISION.

Thanks for doing this. Somehow I forgot to commit my fix for this as
posted to packages@ in early February.

 Jeremy C. Reed

 	  	 	 technical support & remote administration
	  	 	 http://www.pugetsoundtechnology.com/