Bug#663217: zenmap's sys.path includes /tmp locations

2012-03-29 Thread Fyodor
On Fri, Mar 09, 2012 at 02:57:03PM +0100, chrysn wrote: Package: zenmap Version: 5.21-1.1 Severity: grave Tags: security the zenmap script modifies its sys.path to include '/tmp/nmap-5.21/debian/tmp/usr/lib/python2.6/site-packages/', which is inserted at build time from setyp.py. Thank

Bug#663217: zenmap's sys.path includes /tmp locations

2012-03-09 Thread chrysn
Package: zenmap Version: 5.21-1.1 Severity: grave Tags: security the zenmap script modifies its sys.path to include '/tmp/nmap-5.21/debian/tmp/usr/lib/python2.6/site-packages/', which is inserted at build time from setyp.py. as /tmp/nmap-5.21 is not present and therefore not protected on systems