Your message dated Fri, 28 Oct 2016 13:02:06 +0200
with message-id 
<CABJ6WihVyOQk05a=3eQYgLEdUozR-vOAiJJu+erWLq0=4wj...@mail.gmail.com>
and subject line Close by hand due to broken Closes syntax in debian/changelog
has caused the Debian Bug report #605190,
regarding twisted-doc: Use of PYTHONPATH env var in an insecure way
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
605190: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605190
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: twisted-doc
Version: 10.1.0-3
Severity: important
Tags: security
User: [email protected]
Usertags: pythonpath

Jakub Wilk performed an analysis[1] for packages setting PYTHONPATH in
an insecure way. Those packages do something like:

    PYTHONPATH=/spam/eggs:$PYTHONPATH

This is wrong, because if PYTHONPATH were originally unset or empty,
current working directory would be added to sys.path.

[1] http://lists.debian.org/debian-python/2010/11/msg00045.html

Your package turns out to ship vulnerable examples or contains
insecure advices: you can find a complete log at [2].

[2] http://people.debian.org/~morph/mbf/pythonpath.txt

Some guidelines on how to fix these bugs: in the case given above, you
can use something like

    PYTHONPATH=/spam/eggs${PYTHONPATH:+:$PYTHONPATH}

(If you don't known this construct, grep for "Use Alternative Value"
in the bash/dash manpage.)

Also, in cases like

   PYTHONPATH=/usr/lib/python2.5/site-packages/:$PYTHONPATH

or

   PYTHONPATH=$PYTHONPATH:$SPAMDIR exec python $SPAMDIR/spam.py

you shouldn't need to touch PYTHONPATH at all.

Feel free to contact [email protected] in case of
help.



--- End Message ---
--- Begin Message ---
Version: 16.4.1-2

--- End Message ---
_______________________________________________
Python-modules-team mailing list
[email protected]
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

Reply via email to