Bug#308783: RFC: Bug#308783: libxpm4: problems with s_popen (CAN-2004-0914)

2005-05-18 Thread Branden Robinson
: problems with s_popen (CAN-2004-0914) Date: Thu, 12 May 2005 12:59:04 +0200 Message-ID: [EMAIL PROTECTED] List-Id: debian-x.lists.debian.org X-Mailing-List: debian-x@lists.debian.org archive/latest/26382 User-Agent: Mutt/1.5.6+20040907i X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00

Bug#308783: libxpm4: problems with s_popen (CAN-2004-0914)

2005-05-12 Thread Matej Vela
Package: libxpm4 Version: 4.3.0.dfsg.1-12 Severity: grave Justification: may allow access to the accounts of users who use the package The CAN-2004-0914 patch introduced a s_popen() function as a safe replacement for popen(). Instead of invoking a shell, it splits arguments on whitespace and