Bug#881749: redmine: creates world-writable tempdir /tmp/bundler/home

2017-11-19 Thread duck
Control: reassign -1 ruby-bundler Control: tags -1 + security Quack, This repository is created by bundler, and there is no code in the redmine package specifying this repository, so this is using the default Bundler behavior. In fact someone already reported about this directory being

Bug#881749: redmine: creates world-writable tempdir /tmp/bundler/home

2017-11-14 Thread Andreas Beckmann
Package: redmine Version: 3.3.1-4 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Control: affects -1 + redmine-sqlite redmine-mysql redmine-pgsql Hi, during a test with piuparts I noticed your package behaves strangely while upgrading from 'stretch' to 'buster'. There is