bug-guix
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#37744: Per-user profile directory hijack (CVE-2019-17365 for Nix)


From: pelzflorian (Florian Pelz)
Subject: bug#37744: Per-user profile directory hijack (CVE-2019-17365 for Nix)
Date: Wed, 16 Oct 2019 16:22:21 +0200
User-agent: NeoMutt/20180716

Thank you for ensuring security issues are fixed.

On Wed, Oct 16, 2019 at 12:22:33PM +0200, Ludovic Courtès wrote:
> +This is now fixed by letting @command{guix-daemon} create these directories 
> on
> +behalf of users and removing the world-writable permissions on
> +@code{per-user}.  On multi-user systems, we recommend updating the daemon 
> now.
> +To do that, run @code{sudo guix pull} if you're on a foreign distro, or run
> +@code{sudo guix pull && sudo guix system reconfigure @dots{}} on Guix
> +System.")))

Why sudo guix pull?  It should be without sudo, am I wrong?

I will translate now and submit a patch.

Regards,
Florian





reply via email to

[Prev in Thread] Current Thread [Next in Thread]