[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#671255: CVE-2012-2451: CWE-377 Insecure Temporary File



On Mon, 07 May 2012 00:04:35 +0200, Cyril Brulebois wrote:

> > > Specifically, a loss of error handling. […]
> > Hm, good catch.
> > Maybe it's better to give this a second look ...
> Given the above, it very much looks like fixing that bug properly in
> unstable first (which is what we encourage all the time anyway), taking
> some time to think about it, would be better than hurrying up.

Agreed.
Thanks for taking the time to review the diff and point out this
issue!
 
I've now opened an upstream ticket:
https://rt.cpan.org/Ticket/Display.html?id=77039

Cheers,
gregor

-- 
 .''`.  Homepage: http://info.comodo.priv.at/ - OpenPGP key 0xBB3A68018649AA06
 : :' : Debian GNU/Linux user, admin, and developer  -  http://www.debian.org/
 `. `'  Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe
   `-   NP: Bruce Springsteen: Waitin' on a Sunny Day

Attachment: signature.asc
Description: Digital signature


Reply to: