Re: security of devel/cscope

2006-06-18 Thread Joachim Schipper
On Sat, Jun 17, 2006 at 01:56:45AM -0500, Jolan Luff wrote: On Sat, Jun 17, 2006 at 06:00:27AM +0200, Tobias Ulmer wrote: snip While i like this tool well, the attitude of the main developer regarding security issues is very disturbing. (The bugtracker of the project and securityfocus

Re: security of devel/cscope

2006-06-17 Thread Jolan Luff
On Sat, Jun 17, 2006 at 06:00:27AM +0200, Tobias Ulmer wrote: snip While i like this tool well, the attitude of the main developer regarding security issues is very disturbing. (The bugtracker of the project and securityfocus are a good read on that) My question is, should we bother and

security of devel/cscope

2006-06-16 Thread Tobias Ulmer
Hi, i've looked into the sourcecode of cscope over the last few weeks because i got alarmed by a advisory from Debian. I knew that the port was old, so i thought, lets create some patches for the outstanding issues: - CVE-2004-0996 Insecure creation of temporary files, fixed in cvs. The