[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: zoo: directory traversal security bug



On Fri, 2005-07-15 at 06:53 -0700, Richard A. Hecker wrote:

> That is true, but we do have an obligation to our users.  Every DD makes 
> mistakes.  What is the
> chance they might upload something that contains a Trojan if they do not 
> know the source?  How
> would they be able to check a claim if they cannot program in the source 
> language?

Oh .. which DD can be responsible for my package Felix then?
They would have to know:

* C/C++
* OCaml
* Python
* Bash
* Interscript
* Felix
* ocamllex/ocamlyacc and Elkhound
* HTML/XML
* Latex/troff/texinfo
* snippets of 10 other programming languages

.. hmm .. and understanding the languages is just the start.

Heck, I don't understand it all .. and I wrote most of it :)

-- 
John Skaller <skaller at users dot sourceforge dot net>

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: