[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#610384: libparallel-forkmanager-perl: new upstream version



-=| John Lightsey, 18.05.2011 20:25:09 -0500 |=-
> tags 610384 + wontfix
> thanks
> 
> The handling of files in /tmp with Parallel::Forkmanager 0.7.6+ is very
> insecure.
> 
> http://rt.cpan.org/Ticket/Display.html?id=68298

Dear John,

It seems to me that the current upstream version (1.03) of 
Parallel::ForkManager is better in handling temporary files. Although 
all the files still use predictable names, they are all created in 
a directory created by File::Temp::tmpdir, which should be safe enough 
AIUI.

Maybe you would consider uploading an updated package? Experimental 
should be fine if you don't want to disturb the freeze.


As an alternative, in case you don't have time for this package, 
I offer to take it over to the pkg-perl team (which you are welcome to 
join too).

Best regards,
    dam


Reply to: