Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-27 Thread Gunnar Wolf
Chris Karakas dijo [Tue, Nov 25, 2008 at 10:39:23AM +0100]: > Hello all, > > I definitely oppose the proposed patch and will NOT accept it in chm2pdf (I > am one of the two authors)! > > Reasons: > > 1) There are easier ways to avoid the security risks. > 2) It destroys the "--dontextract" opti

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-25 Thread Chris Karakas
Hello all, I definitely oppose the proposed patch and will NOT accept it in chm2pdf (I am one of the two authors)! Reasons: 1) There are easier ways to avoid the security risks. 2) It destroys the "--dontextract" option which is a *very* useful one! Let me propose an alternative: It all has

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-01 Thread Nico Golde
Hi Steve, * Steve Stalcup <[EMAIL PROTECTED]> [2008-11-01 14:55]: > I'm just waiting for a sponsor upload. I have uploaded the fix into ubuntu > 8.10 I can sponsor the upload if you want. Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reason

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-01 Thread Steve Stalcup
Hi Nico, I'm just waiting for a sponsor upload. I have uploaded the fix into ubuntu 8.10 Steve -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-01 Thread Nico Golde
Hi Steve, any reason this hasn't yet been uploaded? Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpnQVH65Jwco.pgp Description: PGP signature

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-10-11 Thread Steve Stalcup
Thanks for the report -Steve On Oct 11, 2008, at 7:43 PM, Karol Lewandowski <[EMAIL PROTECTED]> wrote: Package: chm2pdf Version: 0.9-2 Severity: grave Justification: causes non-serious data loss There are several problems with this package: 1. chm2pdf creates /tmp/chm2pdf/{orig,work}/X direc

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-10-11 Thread Karol Lewandowski
Package: chm2pdf Version: 0.9-2 Severity: grave Justification: causes non-serious data loss There are several problems with this package: 1. chm2pdf creates /tmp/chm2pdf/{orig,work}/X directories. (Where X is file basename, foo for foo.chm). This makes script unusable for other users, i.