Bug#317989: security hole or not, this is an existant bug

2005-08-03 Thread Brian May
CC: debian security team, they set security policy, not me. > "Joey" == Joey Hess <[EMAIL PROTECTED]> writes: Joey> I don't really want to argue about whether this is a securty Joey> hole or try to dream up scenarios where compromised backups Joey> are used to exploit a system dur

Bug#317989: security hole or not, this is an existant bug

2005-08-03 Thread Joey Hess
I don't really want to argue about whether this is a securty hole or try to dream up scenarios where compromised backups are used to exploit a system during a restore. If you don't think it's a security hole, that's fine. However, the fact that the package is statically linked to a version of gzip