[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: CVE against the fwknop package



On Wed, Oct 10, 2012 at 21:29:18 +0200, Franck Joncourt wrote:

> Hi,
> 
> I have prepared an upload for squeeze to fix the CVEs against the
> 2.0.0rc2 release. I have enclosed a debdiff.
> The new package will be named fwknop_2.0.0rc2-2+deb7u1.dsc. It is
> targetted for the testing-proposed-updates with urgency set to high.
> 
> Can someone check the update so that I can upload the package?
> 
The diff looks mostly ok, though checking for S_ISLNK from stat(2) seems
useless, and I'm not quite sure why the chmod is done *after* writing
the config file rather than upfront.

Cheers,
Julien

Attachment: signature.asc
Description: Digital signature


Reply to: