[Secure-testing-team] Bug#650707: libpar-perl: PAR packed files are extracted to unsafe and predictable temporary directories

2011-12-01 Thread Salvatore Bonaccorso
Package: libpar-perl Version: 1.002-1 Severity: important Tags: security Hi Changelog for new upstream release of libpar-perl contains: [Changes for 1.004 - Nov 30, 2011] - back out r1241: it causes errors in PAR::Packer's test suite - change "unsafe directory" error message to match the wor

[Secure-testing-team] Bug#650706: libpar-packer-perl: PAR packed files are extracted to unsafe and predictable temporary directories

2011-12-01 Thread Salvatore Bonaccorso
Package: libpar-packer-perl Version: 1.010-1 Severity: important Tags: security Hi Changelog for 1.011 contains: - RT #69560/CVE-2011-4114: PAR packed files are extracted to unsafe and predictable temporary directories - create parent of cache directory (i.e. /tmp/par-USER) with mod