Bug#656388: tucan: insecure update mechanism

2012-03-18 Thread Jonathan Wiltshire
Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.6) - use target

Bug#656388: tucan: insecure update mechanism

2012-01-18 Thread A. N. Other
Package: tucan Version: 0.3.9-1 Severity: grave Tags: security Justification: user security hole Tucan comes with "plugins" to handle downloads from the various download sites it supports. These plugins are basically python modules which run with the same permissions as the user running tucan. The