Re: patch / CVE-2018-1000156

2018-04-12 Thread Chris Lamb
Brian, > Not sure I understand this comment from dla-needed.txt: Sorry, I did not see your comment until now. > The patch - good version at [..] doesn't touch the files noted > above. The patch adds a call to make_tempfile (or similar) which uses utility functions from these aforementioned file

patch / CVE-2018-1000156

2018-04-11 Thread Brian May
Not sure I understand this comment from dla-needed.txt: NOTE: 20180407: of a rabbit-hole with respect all the newer "safe_" foo. I suspect if we can just avoid calling NOTE: 20180407: make_tempfile (from src/util.c) and safe_unlink (from src/safe.c) then we can avoid most of this. (lamby) The pa