Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
motion vulnerability
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
ysbeer
n00b
n00b


Joined: 08 Jul 2016
Posts: 65

PostPosted: Sat Jul 16, 2016 10:44 am    Post subject: motion vulnerability Reply with quote

https://bugs.gentoo.org/show_bug.cgi?id=475120

Above link points to a vulnerability in the motion camera software.

Question: is motion safe to use on Gentoo?
Back to top
View user's profile Send private message
Hu
Moderator
Moderator


Joined: 06 Mar 2007
Posts: 13493

PostPosted: Sat Jul 16, 2016 4:08 pm    Post subject: Reply with quote

As I read that thread, the ebuild in tree as of the last developer comment still has the cited vulnerabilities. There is interest in providing a non-vulnerable version, but that has not been published to Portage yet. In the meantime, "safe" depends on whether your installation can be accessed in a way necessary to provoke the vulnerabilities. Even an unlocked door can be "safe" if the only people who can reach it can be trusted not to abuse the lack of a lock.
Back to top
View user's profile Send private message
ysbeer
n00b
n00b


Joined: 08 Jul 2016
Posts: 65

PostPosted: Sat Jul 16, 2016 6:49 pm    Post subject: Reply with quote

Hu wrote:
As I read that thread, the ebuild in tree as of the last developer comment still has the cited vulnerabilities. There is interest in providing a non-vulnerable version, but that has not been published to Portage yet. In the meantime, "safe" depends on whether your installation can be accessed in a way necessary to provoke the vulnerabilities. Even an unlocked door can be "safe" if the only people who can reach it can be trusted not to abuse the lack of a lock.


thanks for your response, i will not be using it then, until they patch it, because the vulnerability seems to be possibly exploited when visiting a malicious website crafted for the exploit.
Back to top
View user's profile Send private message
tnt
Veteran
Veteran


Joined: 27 Feb 2004
Posts: 1171

PostPosted: Tue Dec 06, 2016 11:04 pm    Post subject: Reply with quote

can we expect update of this package or we have to search for some alternative?
_________________
gentoo user
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum