Bug#496358: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496358 important thanks The vulnerable script in this package is /usr/share/games/crossfire/maps/Info/combine.pl, which is not used by default; it's provided only as a utility for possible use. I don't think this should be considered grave. -- Steve Langasek Give me

Bug#496358: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dmitry E. Oboukhov
Package: crossfire-maps Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts of packages (marked as executable) were tested. In some packages I've discovered scripts with