Control: tags -1 + confirmed On Wed, 2016-06-15 at 11:12 +0200, Petter Reinholdtsen wrote: > On my Debian Jessie machine, I would like to fix a security problem with > automake-1.14 that show up the debsecan report, see > <URL: > https://security-tracker.debian.org/tracker/source-package/automake-1.14 >. > The issue never got a CVE (no reply to the request), so I point to the > source package entry instead of the some times changing TEMP reference. > > The issue is fixed in automake-1.15, but not in automake-1.14 that is in > stable but removed from unstable. > > The issue is unsafe use of /tmp/. The patch is similar to the code in > version 1.15. > > OK to upload?
Assuming that the resulting package has been tested on stable, please go ahead, except: +automake-1.14 (1:1.14.1-4+deb8u1) unstable; urgency=medium That distribution is a little wrong. :-p "jessie", please. Regards, Adam