Bug#605159: gnumed-client: Use of PYTHONPATH env var in an insecure way

2010-12-05 Thread Mehdi Dogguy
On 11/30/2010 05:25 PM, Andreas (Debian) wrote: Hi, thanks to the support of upstream there is a new release which fixes the issue. However, the issue does not even really exist in *effective* upstream code - it is just contained in a *comment* which is simlpy activated in a patch in the

Bug#605159: gnumed-client: Use of PYTHONPATH env var in an insecure way

2010-11-30 Thread Andreas (Debian)
Hi, thanks to the support of upstream there is a new release which fixes the issue. However, the issue does not even really exist in *effective* upstream code - it is just contained in a *comment* which is simlpy activated in a patch in the Debian packaging. So I wonder what might be the best

Bug#605159: gnumed-client: Use of PYTHONPATH env var in an insecure way

2010-11-30 Thread Karsten Hilbert
On Tue, Nov 30, 2010 at 05:25:00PM +0100, Andreas (Debian) wrote: thanks to the support of upstream there is a new release which fixes the issue. However, the issue does not even really exist in *effective* upstream code - it is just contained in a *comment* which is simlpy activated in a

Bug#605159: gnumed-client: Use of PYTHONPATH env var in an insecure way

2010-11-29 Thread Karsten Hilbert
Fixed upstream in 0.7.10 and 0.8.5. Please consider 0.7.10 for migration to squeeze. Changelog: 0.7.10 FIX: exception on trying to create hospital stay w/o episode [thanks devm] FIX: properly set PYTHONPATH [thanks JB and Debian Squeeze (#605159)] Download:

Bug#605159: gnumed-client: Use of PYTHONPATH env var in an insecure way

2010-11-27 Thread Sandro Tosi
Package: gnumed-client Version: 0.8.4-1 Severity: grave Tags: security User: debian-pyt...@lists.debian.org Usertags: pythonpath Jakub Wilk performed an analysis[1] for packages setting PYTHONPATH in an insecure way. Those packages do something like: PYTHONPATH=/spam/eggs:$PYTHONPATH This