severity 496415 important
thanks

On Sun, Aug 24, 2008 at 10:05:29PM +0400, Dmitry E. Oboukhov wrote:
> In some packages I've discovered scripts with errors which may be used
> by a user for damaging important system files or user's files.

I'm fully aware of what a symlink overrun is. As for tiger, the one you've
found in the 'genmsgidx' script exists but is not that important, that script
is actually used only when the package is built it not used when any of the
Tiger scripts are run as root.

I will fix the bug for the benefit of those who autobuild packages in
untrusted systems, but I'm lowering its severity.

Regards

Javier

Attachment: signature.asc
Description: Digital signature

Reply via email to