[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#671255: CVE-2012-2451: CWE-377 Insecure Temporary File



gregor herrmann <gregoa@debian.org> (06/05/2012):
> > Specifically, a loss of error handling. […]

Yeah, my bad. Shouldn't try and mix paracetamol and s-p-u diff reviews…
Sorry about that.

> Hm, good catch.
> (tempfile() indeed just croak()s on errors according to the
> documentation).
> 
> Maybe it's better to give this a second look ...

Given the above, it very much looks like fixing that bug properly in
unstable first (which is what we encourage all the time anyway), taking
some time to think about it, would be better than hurrying up.

→ Next point release.

Mraw,
KiBi.

Attachment: signature.asc
Description: Digital signature


Reply to: