Package: coreutils
Version: 5.97-5
Severity: normal

Steps to reproduce the bug:
1. make a pdf begining with "-p", eg. "-pfoobar.pdf" in Konquerror 
(touch won´t work)
2. start a console and change to the directory where the file is
3. type ls -a *.pdf
4. Notice that the file starting with "-p" is not listet.
5. Type kpdf "./-pfoobar.pdf" now kpdf starts with the file.

I think this is a possible security risk, cause it is possible to hide 
files. But if you use "ls" without any parameters the file is shown. 
Because of this, I used severity normal and nothing higher.

Cheers Stefan

-- System Information:
Debian Release: 4.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.19.2-grsec
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages coreutils depends on:
ii  libacl1                     2.2.41-1     Access control list shared library
ii  libc6                       2.3.6.ds1-10 GNU C Library: Shared libraries
ii  libselinux1                 1.32-3       SELinux shared libraries

coreutils recommends no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to