Re: Bug#810799: libcgi-session-perl: Perl DSA-3441-1 exposes taint bug in CGI::Session::Driver::file

2016-01-12 Thread Chris Boot
On 12/01/16 15:27, Salvatore Bonaccorso wrote: > My gut feeling about this: Since the issue was already present before, > uncovered indirectly by the perl DSA, and currently affects twiki (not > packaged in Debian), I would tend to ask the SRM to have the fix for > libcgi-session-perl to be schedul

Re: Bug#810799: libcgi-session-perl: Perl DSA-3441-1 exposes taint bug in CGI::Session::Driver::file

2016-01-12 Thread Salvatore Bonaccorso
Hi, On Tue, Jan 12, 2016 at 01:38:51PM +, Dominic Hargreaves wrote: > Control: tags -1 - security > Control: found -1 4.46-1 > > On Tue, Jan 12, 2016 at 12:54:19PM +, Chris Boot wrote: > > Control: tag -1 security > > > > On 12/01/16 12:28, Chris Boot wrote: > > [snip] > > > Forwarded: h

Re: Bug#810799: libcgi-session-perl: Perl DSA-3441-1 exposes taint bug in CGI::Session::Driver::file

2016-01-12 Thread Dominic Hargreaves
Control: tags -1 - security Control: found -1 4.46-1 On Tue, Jan 12, 2016 at 12:54:19PM +, Chris Boot wrote: > Control: tag -1 security > > On 12/01/16 12:28, Chris Boot wrote: > [snip] > > Forwarded: https://rt.cpan.org/Public/Bug/Display.html?id=80346 > > > > Dear Maintainer, > > > > With

Re: Bug#810799: libcgi-session-perl: Perl DSA-3441-1 exposes taint bug in CGI::Session::Driver::file

2016-01-12 Thread Chris Boot
Control: tag -1 security On 12/01/16 12:28, Chris Boot wrote: [snip] > Forwarded: https://rt.cpan.org/Public/Bug/Display.html?id=80346 > > Dear Maintainer, > > With Perl upgraded from 5.20.2-3+deb8u1 to 5.20.2-3+deb8u2, our > installation of TWiki (http://twiki.org/) no longer functions. This >