Bug#496378: The possibility of attack with the help of symlinks in some Debian packages

2008-09-08 Thread Chris Lamb
Moritz Muehlenhoff wrote: However, I have some doubts whether this should be fixed or gdrae rather be removed altogether I would tend to agree. However, I'm going to upload the NMU anyway because it's simple and is security-related. Would you like to try and contact upstream and see if there

Bug#496378: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Moritz Muehlenhoff
On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: Package: gdrae Severity: grave Hi, maintainer! gdrae is indeed vulnerable to temp file attacks through /tmp/gdrae/palabra However, I have some doubts whether this should be fixed or gdrae rather be removed altogether: It

Bug#496378: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dmitry E. Oboukhov
Package: gdrae Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts of packages (marked as executable) were tested. In some packages I've discovered scripts with errors which