CVE-2008-5138 pam_mount insecure tempfile creation - to update or not?

2008-11-21 Thread Till Maas
Hiyas, there was a bug report opened because of an possible vulnerability in pam_mount, which I would not really consider one. Because it cannot be triggered under normal circumstances because the script would fail before an insecure tempfile is used. More details are available here: https://b

Re: CVE-2008-5138 pam_mount insecure tempfile creation - to update or not?

2008-11-23 Thread Tomas Hoger
Hi Till! Comment added to BZ as well... On Fri, 21 Nov 2008 22:51:32 +0100 Till Maas <[EMAIL PROTECTED]> wrote: > https://bugzilla.redhat.com/show_bug.cgi?id=472109#c2 > > The question is now, whether I should update the package without the > affected script to make everyone aware of this or ju