Bug#448319: opens /tmp/vobcopy.bla insecurely, symlink attack

2007-10-31 Thread Nico Golde
Hi, CVE-2007-5718 has been assigned to this bug. Please include the CVE id in your changelog. Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpIO0a41DEYe.pgp Description: PGP

Bug#448319: opens /tmp/vobcopy.bla insecurely, symlink attack

2007-10-27 Thread Joey Hess
Package: vobcopy Version: 0.5.14-2 Severity: important Tags: security vobcopy -q opens /tmp/vobcopy.bla insecurely: open(/tmp/vobcopy.bla, O_WRONLY|O_CREAT|O_APPEND|O_LARGEFILE, 0666) = 2 Similarly, vopbcopy -v -v opens /tmp/vobcopy_0.5.14.log insecurely: open(/tmp/vobcopy_0.5.14.log,