Gyorgy Sarvari dd81ffdb68
ez-ipupdate: patch CVE-2003-0887
Details: https://nvd.nist.gov/vuln/detail/CVE-2003-0887

The vulnerability is about the default (example) configurations,
which place cache files into the /tmp folder, that is world-writeable.
The recommendation would be to place them to a more secure folder.

The recipe however does not install these example configurations,
and as such it is not vulnerable either.

Just to make sure, patch these folders to a non-tmp folder
(and also install that folder, empty).

Some more discussion about the vulnerability:
https://bugzilla.suse.com/show_bug.cgi?id=48161

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-02-02 19:54:39 -08:00
..
2026-01-20 08:27:11 -08:00
2025-07-07 10:00:53 -07:00
2025-12-10 08:56:12 -08:00
2025-12-02 09:22:49 -08:00
2025-02-27 20:28:17 +00:00
2025-11-08 06:53:05 -08:00
2025-08-13 08:01:50 -07:00
2026-01-12 10:25:56 -08:00
2025-03-20 08:46:55 -07:00
2025-07-15 00:25:32 -07:00
2025-11-10 20:31:54 -08:00
2023-02-20 00:23:02 -08:00
2025-12-08 23:22:19 -08:00