Bug#683998: [Packaging] Bug#683998: munin: allows creation of sockets at arbitrary locations (/tmp file vulnerability)

2012-09-03 Thread Holger Levsen
for fixing 1.4.x: the fix was in bcdb2795 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#683998: munin: allows creation of sockets at arbitrary locations (/tmp file vulnerability)

2012-08-06 Thread Helmut Grohne
Package: munin Version: 1.4.5-3 Severity: serious Tags: security I wondered where a socket /tmp/munin-master-processmanager-12345.sock would come from and whether it was created in a secure way. In the presence of this bug report you may have guessed, that it is not. The corresponding code can be

Bug#683998: munin: allows creation of sockets at arbitrary locations (/tmp file vulnerability)

2012-08-06 Thread Helmut Grohne
Control: fixed 683998 2.0.1-1 Control: tags 683998 + patch As said in my previous mail the issue stems from the rundir default. This variable is set in /usr/share/perl5/Munin/Master/Config.pm. In the wheezy version rundir is changed to MUNIN_STATEDIR, so wheezy is not affected. I would assume

Bug#683998: [Packaging] Bug#683998: munin: allows creation of sockets at arbitrary locations (/tmp file vulnerability)

2012-08-06 Thread Holger Levsen
On Montag, 6. August 2012, Helmut Grohne wrote: Control: fixed 683998 2.0.1-1 Control: tags 683998 + patch ack + thanks. expect an upload soon. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org