Re: List of bugs that *must* be fixed before releasing Hamm
>>>>> "jdassen" == jdassen <jdassen@wi.leidenuniv.nl> writes:
jdassen> These bugs are out of my league. I have tried to get the
jdassen> attention of the folks on egcs-bugs, but failed.
>> gcc 19453 altgcc still vulnerable to /tmp symlink attack. [72]
>> (Galen Hazelwood <galenh@micron.net>)
jdassen> This bug pertains to all GNU / egcs C compilers and
jdassen> derivatives. I've produced what I hope to be a fix; this
jdassen> has been forwarded to the egcs-bugs mailing list and I'm
jdassen> currently awaiting feedback. Although I haven't verified
jdassen> this closely, I suspect altgcc, gcc etc. can be fixed in
jdassen> a similar manner.
Perhaps it will prove fruitful to check with Red Hat; they may have a
patch in 5.1 that fixes this. Looking on their errata page for 5.0
reveals quite a few `tmp race' bug fixes.
--
To UNSUBSCRIBE, email to debian-qa-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply to: