Bug#901572: acccheck: CVE-2018-12268: Patch proposal

2018-09-03 Thread Phil.
Okay, From what I've seen, the code is effectively just horrible ! Thanks for adding the affect tag, as I've haven't seen the removal request. Cheers, Le 3 septembre 2018 11:07:08 GMT+02:00, Raphael Hertzog a écrit : >Control: affects 904200 acccheck > >On Mon, 03 Sep 2018,

Bug#901572: acccheck: CVE-2018-12268: Patch proposal

2018-09-03 Thread Raphael Hertzog
Control: affects 904200 acccheck On Mon, 03 Sep 2018, p...@reseau-libre.net wrote: > I've updated the acccheck.pl behavior to correct (i hope) the > CVE-2018-12268. User and password input files are sanitized before any use > in the generated commandline string. The patch is given attached to

Bug#901572: acccheck: CVE-2018-12268: Patch proposal

2018-09-03 Thread phil
tags 901572 + patch user p...@reseau-libre.net usertags pkg-security-team thanks Hello, I've updated the acccheck.pl behavior to correct (i hope) the CVE-2018-12268. User and password input files are sanitized before any use in the generated commandline string. The patch is given attached to