[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Uploaded devscripts 2.0.0 (source all) to master



> On Thu, Jan 07, 1999 at 11:05:41AM -0800, Joey Hess wrote:
> > Julian Gilbey wrote:
> > >    * Now debchange works on a version of the changelog in /tmp and only
> > >      overwrites the current changelog if everything is OK; this is much
> > >      safer than the original version.  Also, all system calls have their
> > >      return status checked
> > 
> > Did you do this safely? Ie, did you protect against file in /tmp exploits?
> 
> And /PLEASE/ tell me you don't mean /tmp but $TMPDIR with a default back
> to /tmp?

Both of these are fixed in version 2.0.2 which I am about to upload.

   Julian

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

            Julian Gilbey             Email: J.D.Gilbey@qmw.ac.uk
       Dept of Mathematical Sciences, Queen Mary & Westfield College,
                  Mile End Road, London E1 4NS, ENGLAND
      -*- Finger jdg@goedel.maths.qmw.ac.uk for my PGP public key. -*-


Reply to: