Bug#344029: Insecure /tmp file handling in libmail-audit-perl in Sarge (+patch)

2006-01-15 Thread Martin Schulze
Gunnar Wolf wrote:
 Martin Schulze dijo [Sat, Jan 14, 2006 at 08:43:57AM +0100]:
  Gunnar Wolf wrote:
   Hi,
   
   The bug is indeed important, even if it is not easily exploitable, and
   the fix is trivial. I am pushing it to the security team so they can
   apply it to the version in Sarge as well.
  
  Please use CVE-2005-4536 for this problem.
  
  Are you in contact with upstream?
 
 Upstream has abandoned this package and suggest replacing it - But
 it's present in Sarge (the complete information is in the bug
 report). 

Ok.  I'll prepare a DSA with updates for sarge and woody.

Regards,

Joey

-- 
Given enough thrust pigs will fly, but it's not necessarily a good idea.

Please always Cc to me when replying to me on the lists.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#344029: Insecure /tmp file handling in libmail-audit-perl in Sarge (+patch)

2006-01-14 Thread Gunnar Wolf
Martin Schulze dijo [Sat, Jan 14, 2006 at 08:43:57AM +0100]:
 Gunnar Wolf wrote:
  Hi,
  
  The bug is indeed important, even if it is not easily exploitable, and
  the fix is trivial. I am pushing it to the security team so they can
  apply it to the version in Sarge as well.
 
 Please use CVE-2005-4536 for this problem.
 
 Are you in contact with upstream?

Upstream has abandoned this package and suggest replacing it - But
it's present in Sarge (the complete information is in the bug
report). 

-- 
Gunnar Wolf - [EMAIL PROTECTED] - (+52-55)1451-2244 / 5623-0154
PGP key 1024D/8BB527AF 2001-10-23
Fingerprint: 0C79 D2D1 2C4E 9CE4 5973  F800 D80E F35A 8BB5 27AF


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#344029: Insecure /tmp file handling in libmail-audit-perl in Sarge (+patch)

2006-01-13 Thread Gunnar Wolf
Hi,

The bug is indeed important, even if it is not easily exploitable, and
the fix is trivial. I am pushing it to the security team so they can
apply it to the version in Sarge as well.

Greetings,

-- 
Gunnar Wolf - [EMAIL PROTECTED] - (+52-55)1451-2244 / 5623-0154
PGP key 1024D/8BB527AF 2001-10-23
Fingerprint: 0C79 D2D1 2C4E 9CE4 5973  F800 D80E F35A 8BB5 27AF


signature.asc
Description: Digital signature


Bug#344029: Insecure /tmp file handling in libmail-audit-perl in Sarge (+patch)

2006-01-13 Thread Martin Schulze
Gunnar Wolf wrote:
 Hi,
 
 The bug is indeed important, even if it is not easily exploitable, and
 the fix is trivial. I am pushing it to the security team so they can
 apply it to the version in Sarge as well.

Please use CVE-2005-4536 for this problem.

Are you in contact with upstream?

Regards,

Joey

-- 
If nothing changes, everything will remain the same.  -- Barne's Law

Please always Cc to me when replying to me on the lists.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]