Bug#609474: potential symlink attack when compiling tendra

2011-01-09 Thread Simon McVittie
Package: tendra Version: 4.1.2-18 Severity: normal Tags: patch security tendra's ./INSTALL script writes to (for instance) /var/tmp/tuname_$$, which is predictable enough to be open to symlink attacks while compiling the package. I'm not setting the usual grave severity for security bugs, since

Bug#609474: potential symlink attack when compiling tendra

2011-01-09 Thread Mark Brown
On Sun, Jan 09, 2011 at 06:55:08PM +, Simon McVittie wrote: A patch follows; it'll also be available in http://git.debian.org/?p=users/smcv/qa/tendra.git shortly. You need to at a minimum specify a branch as well if you want people to take stuff via git. -- To UNSUBSCRIBE, email to

Bug#609474: potential symlink attack when compiling tendra

2011-01-09 Thread Simon McVittie
On Sun, 09 Jan 2011 at 19:11:57 +, Mark Brown wrote: On Sun, Jan 09, 2011 at 06:55:08PM +, Simon McVittie wrote: A patch follows; it'll also be available in http://git.debian.org/?p=users/smcv/qa/tendra.git shortly. You need to at a minimum specify a branch as well if you want

Bug#609474: potential symlink attack when compiling tendra

2011-01-09 Thread Mark Brown
On Sun, Jan 09, 2011 at 10:14:06PM +, Simon McVittie wrote: On Sun, 09 Jan 2011 at 19:11:57 +, Mark Brown wrote: On Sun, Jan 09, 2011 at 06:55:08PM +, Simon McVittie wrote: A patch follows; it'll also be available in http://git.debian.org/?p=users/smcv/qa/tendra.git shortly.