Date: Sun, 07 Apr 2019 13:37:07 +0000 From: bugzilla-noreply@freebsd.org To: ports-bugs@FreeBSD.org Subject: [Bug 237070] graphics/qgis: installs world-writable files Message-ID: <bug-237070-7788@https.bugs.freebsd.org/bugzilla/>
next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D237070 Bug ID: 237070 Summary: graphics/qgis: installs world-writable files Product: Ports & Packages Version: Latest Hardware: Any OS: Any Status: New Severity: Affects Only Me Priority: --- Component: Individual Port(s) Assignee: ports-bugs@FreeBSD.org Reporter: d8zNeCFG@aon.at CC: rhurlin@gwdg.de Flags: maintainer-feedback?(rhurlin@gwdg.de) CC: rhurlin@gwdg.de Scenario: - Updating qgis using portmaster Result: - Excerpt from the install log: Installing qgis-3.6.0_5... =3D=3D=3D> SECURITY REPORT:=20 This port has installed the following world-writable files/directorie= s. /usr/local/share/qgis/resources/data/contributors.json /usr/local/share/qgis/resources/data/qgis-hackfests.qml /usr/local/share/qgis/resources/data/world_map.shp /usr/local/share/qgis/resources/data/qgis-hackfests.json /usr/local/share/qgis/resources/data/world_map.shx /usr/local/share/qgis/resources/data/world_map.qix /usr/local/share/qgis/resources/data/world_map.prj /usr/local/share/qgis/resources/data/world_map.qml /usr/local/share/qgis/resources/data/contributors.qml /usr/local/share/qgis/resources/data/world_map.dbf If there are vulnerabilities in these programs there may be a security risk to the system. FreeBSD makes no guarantee about the security of ports included in the Ports Collection. Please type 'make deinstall' to deinstall the port if this is a concern. For more information, and contact details about the security status of this software, see the following webpage:=20 https://qgis.org/en/site/ Expected result: - No world-writable files are installed -- Martin --=20 You are receiving this mail because: You are the assignee for the bug.=
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-237070-7788>