Re: [SECURITY] [DSA 945-1] New antiword packages fix insecure temporary file creation

2006-01-19 Thread Javier Fernández-Sanguino Peña
On Tue, Jan 17, 2006 at 11:26:51PM +0100, Stefan Wiens wrote: I have reported this problem on Tue, 16 Nov 2004, bug ID #281656. When reporting these bugs please send them to the Security Team, not to the maintainer. Actually, the bug is not even tagged 'security'. Please see

Re: [SECURITY] [DSA 945-1] New antiword packages fix insecure temporary file creation

2006-01-17 Thread Florian Weimer
* Martin Schulze: For the stable distribution (sarge) these problems have been fixed in version 0.35-2sarge1. I would have expected a version like 0.35-1sarge1. The version you have chosen violated an implicit constraint fulfilled by most (all?) security updates: the version of a package

Re: [SECURITY] [DSA 945-1] New antiword packages fix insecure temporary file creation

2006-01-17 Thread Jeroen van Wolffelaar
On Tue, Jan 17, 2006 at 07:59:45PM +0100, Florian Weimer wrote: * Martin Schulze: For the stable distribution (sarge) these problems have been fixed in version 0.35-2sarge1. I would have expected a version like 0.35-1sarge1. The version you have chosen violated an implicit constraint

Re: [SECURITY] [DSA 945-1] New antiword packages fix insecure temporary file creation

2006-01-17 Thread Steve Kemp
On Tue, Jan 17, 2006 at 07:59:45PM +0100, Florian Weimer wrote: AFAICS, this rule is quite reasonable, so I assume that this antiword version is just a minor glitch. Correct? Yes. My fault entirely. It actually took me a while to see what was wrong there - usually I just add 'sargeN' to

Re: [SECURITY] [DSA 945-1] New antiword packages fix insecure temporary file creation

2006-01-17 Thread Stefan Wiens
* Martin Schulze wrote: -- Debian Security Advisory DSA 945-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 17th, 2006