summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMart Raudsepp <leio@gentoo.org>2018-02-23 07:32:58 +0200
committerMart Raudsepp <leio@gentoo.org>2018-02-23 07:32:58 +0200
commita880818f9d0e1f8ae97cd3f94208a48709c032b5 (patch)
tree0283b4f6e801f421d28755949a109af424feffde /profiles
parentx11-libs/wxGTK: remove old (diff)
downloadgentoo-a880818f9d0e1f8ae97cd3f94208a48709c032b5.tar.gz
gentoo-a880818f9d0e1f8ae97cd3f94208a48709c032b5.tar.bz2
gentoo-a880818f9d0e1f8ae97cd3f94208a48709c032b5.zip
profiles: p.mask net-lib/webkit-gtk SLOT=2 and SLOT=3 for security
Bug: https://bugs.gentoo.org/577068
Diffstat (limited to 'profiles')
-rw-r--r--profiles/package.mask10
1 files changed, 10 insertions, 0 deletions
diff --git a/profiles/package.mask b/profiles/package.mask
index b434750712e5..0d29da6bc95e 100644
--- a/profiles/package.mask
+++ b/profiles/package.mask
@@ -30,6 +30,16 @@
#--- END OF EXAMPLES ---
# Mart Raudsepp <leio@gentoo.org> (23 Feb 2018)
+# Old net-libs/webkit-gtk SLOTs have hundreds of known security issues.
+# Use the security safe net-libs webkit-gtk SLOT=4 instead via
+# libraries and applications ported to gtk3 and webkit2gtk API.
+# Masked for removal in 30 days. Bug #577068.
+# Please keep this package.mask entry until at least 25th May 2018 for
+# extra notification of the security vulnerabilities.
+net-libs/webkit-gtk:2
+net-libs/webkit-gtk:3
+
+# Mart Raudsepp <leio@gentoo.org> (23 Feb 2018)
# Older versions of GnuCash use security vulnerable old webkit-gtk slot.
# Use gnucash-2.7.4 or newer instead, but pay attention to the news item:
# https://www.gentoo.org/support/news-items/2018-01-14-gnucash.html