Comment 2 for bug 688418

Revision history for this message
Kees Cook (kees) wrote :

This daemon has unchecked string buffer copies (see nmea_gpgsv() which passes in a string with no length details), and runs as root. These kinds of potential faults should be fixed before it goes into main. I would prefer disabling the geoclue-gypsy backend or doing something to keep this daemon out of main.