Package: perl
Version: 5.10.0-13
Severity: important
Tags: patch fixed-upstream

As discussed in 

  http://rt.perl.org/rt3/Public/Bug/Display.html?id=50322

CGI.pm until 3.33 uses $ENV{TMPDIR} as an sprintf format string, 
which breaks in taint mode starting with Perl 5.10.0.

The fix is trivial, and as the libapache2-mod-perl2 test suite suffers
from this (see #480154) and can't build-depend on a fixed version in
libcgi-pm-perl because of an sbuild bug on the buildds (#395271; see
http://lists.debian.org/debian-release/2008/08/msg00557.html ),
I think we should fix this for lenny.
-- 
Niko Tyni   [EMAIL PROTECTED]



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to