[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [xsawyerx@gmail.com: CVE-2016-1238: Important unsafe module load path flaw]



On Sun, 30 Oct 2016 22:10:36 +0000, Dominic Hargreaves wrote:

> > > > For libnet-dns-perl I tried to adjust the patch from jessie-security
> > > > to sid but I'm not really sure if this is correct and/or sufficent
> > > > (lot's of other 'require's, the same constants also defined in 2 test
> > > > files ...). 
> > > > Maybe you could take a look at this patch/package?
> > > 
> > > Apologies for the severe delay in responding to this. I also noticed
> > > that this package was a bit gnarly when it came to fixing this issue
> > > consistently.
> > > 
> > > Given that '.' has now been removed from @INC by default in sid, I am
> > > inclined not to worry too much about this one now.
> > 
> > Ok, makes sense :)
> > So I guess we can drop the (never uploaded) patch in git?
> 
> Yes, that sounds fine to me.

Thanks; removed in git.


Cheers,
gregor

-- 
 .''`.  Homepage https://info.comodo.priv.at/ - OpenPGP key 0xBB3A68018649AA06
 : :' : Debian GNU/Linux user, admin, and developer -  https://www.debian.org/
 `. `'  Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe
   `-   NP: Die Tontauben: flying

Attachment: signature.asc
Description: Digital Signature


Reply to: