From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 1496C15810F for ; Fri, 9 Jun 2023 17:12:36 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 3A104E08AE; Fri, 9 Jun 2023 17:12:35 +0000 (UTC) Received: from smtp.gentoo.org (woodpecker.gentoo.org [140.211.166.183]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 1D5A9E08AE for ; Fri, 9 Jun 2023 17:12:35 +0000 (UTC) Received: from oystercatcher.gentoo.org (oystercatcher.gentoo.org [148.251.78.52]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 29D1B341075 for ; Fri, 9 Jun 2023 17:12:34 +0000 (UTC) Received: from localhost.localdomain (localhost [IPv6:::1]) by oystercatcher.gentoo.org (Postfix) with ESMTP id B84AEA85 for ; Fri, 9 Jun 2023 17:12:32 +0000 (UTC) From: "Conrad Kostecki" To: gentoo-commits@lists.gentoo.org Content-Transfer-Encoding: 8bit Content-type: text/plain; charset=UTF-8 Reply-To: gentoo-dev@lists.gentoo.org, "Conrad Kostecki" Message-ID: <1686330740.61e56e8c4fa4bd8cad4f093a11d19b4a0d11fd7a.conikost@gentoo> Subject: [gentoo-commits] repo/gentoo:master commit in: profiles/ X-VCS-Repository: repo/gentoo X-VCS-Files: profiles/package.mask X-VCS-Directories: profiles/ X-VCS-Committer: conikost X-VCS-Committer-Name: Conrad Kostecki X-VCS-Revision: 61e56e8c4fa4bd8cad4f093a11d19b4a0d11fd7a X-VCS-Branch: master Date: Fri, 9 Jun 2023 17:12:32 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply X-Archives-Salt: 2eb5bb18-e817-4945-92e6-8d6dc4f55f18 X-Archives-Hash: d6f0421f85bcb135f9efbbf5a91fa488 commit: 61e56e8c4fa4bd8cad4f093a11d19b4a0d11fd7a Author: Conrad Kostecki gentoo org> AuthorDate: Fri Jun 9 17:12:07 2023 +0000 Commit: Conrad Kostecki gentoo org> CommitDate: Fri Jun 9 17:12:20 2023 +0000 URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=61e56e8c app-crypt/acme-sh: drop mask Bug: https://bugs.gentoo.org/908104 Signed-off-by: Conrad Kostecki gentoo.org> profiles/package.mask | 7 ------- 1 file changed, 7 deletions(-) diff --git a/profiles/package.mask b/profiles/package.mask index c02692d60f3d..71b3a22f07e8 100644 --- a/profiles/package.mask +++ b/profiles/package.mask @@ -39,13 +39,6 @@ # Removal on 2023-07-09. Bug #888245. dev-python/doctest-ignore-unicode -# Sam James (2023-06-09) -# Severe security vulnerability: executes arbitrary code returned in responses -# from the server. Appears a CA is abusing that acme-sh uses eval. -# Please see https://github.com/acmesh-official/acme.sh/issues/4659 and -# https://bugs.gentoo.org/908104. -app-crypt/acme-sh - # Georgy Yakovlev (2023-06-08) # May be broken on some arches due to weird LLVM interaction. # Masked for now.