Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Helmut Grohne
Package: git-extras Version: 1.7.0-1.1 Severity: serious Tags: security The git-effort utility uses /tmp/.git-effort as the name of its temporary filename. While this already prevents two users from using this utility (due to not cleaning its temporary file) it also allows for targeted symbolic

Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Rob Browning
tag 698490 +patch thanks Assuming I understood the situation correctly, this might be a plausible fix: From 679c67c615947b44aafa969f00ea00f9ed997e4e Mon Sep 17 00:00:00 2001 From: Rob Browning r...@defaultvalue.org Date: Sat, 19 Jan 2013 10:44:34 -0600 Subject: [PATCH 1/1] Create git-effort

Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Helmut Grohne
On Sat, Jan 19, 2013 at 10:51:23AM -0600, Rob Browning wrote: Assuming I understood the situation correctly, this might be a plausible fix: Yes. Thanks for your quick reaction. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe.

Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Rob Browning
Helmut Grohne hel...@subdivi.de writes: On Sat, Jan 19, 2013 at 10:51:23AM -0600, Rob Browning wrote: Assuming I understood the situation correctly, this might be a plausible fix: Yes. Thanks for your quick reaction. You're certainly welcome, though it was just luck -- happened to be poking