Bug#496360: The possibility of attack with the help of symlinks in some Debian packages

2008-10-10 Thread Tobias Klauser
tags 496360 +patch kthxbye Hi, Attached is a patch which fixes the issue in liguidsoap.py. It makes use of tempfile.mkstemp to create the temporary file and deletes it on exit of liguidsoap (which wasn't the case up to now). I still see a problem with the liquidsoap logfile being written to

Bug#496360: The possibility of attack with the help of symlinks in some Debian packages

2008-10-10 Thread Julien Cristau
On Fri, Oct 10, 2008 at 17:39:09 +0200, Tobias Klauser wrote: I still see a problem with the liquidsoap logfile being written to /tmp [1]. The filename there is only depended on the PID of the liquidsoap process. Unfortunately I lack OCaml hacking skills so I didn't patch this one. [1]

Bug#496360: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Steve Langasek
severity 496360 grave thanks On Mon, Aug 25, 2008 at 11:36:37AM +0400, Dmitry E. Oboukhov wrote: tags 496360 -moreinfo tags 496360 -unreproducible thanks SL Your bug report contains *no* information about the liquidsoap package. SL Where is the vulnerability? following by link in bugreport

Bug#496360: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496360 normal tags 496360 moreinfo unreproducible thanks Your bug report contains *no* information about the liquidsoap package. Where is the vulnerability? -- Steve Langasek Give me a lever long enough and a Free OS Debian Developer to set it on,

Bug#496360: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dmitry E. Oboukhov
Package: liguidsoap Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts of packages (marked as executable) were tested. In some packages I've discovered scripts with errors