[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#496361: The possibility of attack with the help of symlinks in some Debian packages



found 496361 1:2.4.1-6
notfound 496361 1:3.0.0~beta2-1
notfound 496361 2.0.4.dfsg.2-7etch5
tag 496361 + pending
thanks

Dmitry E. Oboukhov wrote:
>     #!/bin/sh
>     URI_ENCODE="`dirname $0`/uri-encode"
>     
>     echo "$@" > /tmp/log.obr.$$
>     echo "$#" >> /tmp/log.obr.$$
[...]

Oops, I didn't see it because I checked in the 3.0 packages which don't have it
anymore..

(Only 2.4.1 is affected)

Regards,

Rene



Reply to: