Processed: Re: Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 598421 pending Bug #598421 [salome] salome: CVE-2010-3377: insecure library loading Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 598421: http://bugs.debian.org/cgi-bin/bugreport.cgi?b

Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-30 Thread Adam C Powell IV
tags 598421 pending thanks On Wed, 2010-09-29 at 23:24 -0500, Raphael Geissert wrote: > On 29 September 2010 22:01, Adam C Powell IV wrote: > > On Tue, 2010-09-28 at 21:07 +, Raphael Geissert wrote: > > Would a secure change omit the former LD_LIBRARY_PATH? That is, would > > it fix this in

Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-29 Thread Raphael Geissert
On 29 September 2010 22:01, Adam C Powell IV wrote: > On Tue, 2010-09-28 at 21:07 +, Raphael Geissert wrote: > Would a secure change omit the former LD_LIBRARY_PATH?  That is, would > it fix this in runSalome to say: > > export LD_LIBRARY_PATH=${prefix}/lib:${libdir}:/usr/lib:/usr/local/lib >

Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-29 Thread Adam C Powell IV
Hello, On Tue, 2010-09-28 at 21:07 +, Raphael Geissert wrote: > Package: salome > Version: 5.1.3-9 > Severity: grave > Tags: security > User: t...@security.debian.org > Usertags: ldpath > > Hello, > > During a review of the Debian archive, I've found your package to > contain a script that c

Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-28 Thread Raphael Geissert
Package: salome Version: 5.1.3-9 Severity: grave Tags: security User: t...@security.debian.org Usertags: ldpath Hello, During a review of the Debian archive, I've found your package to contain a script that can be abused by an attacker to execute arbitrary code. The vulnerability is introduced b