[Python-modules-team] Bug#652653: python-virtualenv: insecure /tmp file handling

2011-12-20 Thread Nico Golde
dates", there's an implied "by talking to the release team" > attached. We're generally not involved in such discussions until after > the security team have decided they don't want to issue a DSA for a > particular issue and someone raises it with us. We will n

[Python-modules-team] Bug#652653: python-virtualenv: insecure /tmp file handling

2011-12-19 Thread Nico Golde
Package: python-virtualenv Version: 1.4.9-3 Severity: grave Tags: patch Hi, it was discovered that python-virtualenv is handling /tmp files in an insecure manner. The following patch fixed this problem: https://bitbucket.org/ianb/virtualenv/changeset/8be37c509fe5 A CVE id for this issue has been