Uploaded mtools 3.9.6-3.1 (source i386) to master
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.6
Date: Sun, 20 Feb 2000 16:01:47 +0100
Source: mtools
Binary: mtools
Architecture: source i386
Version: 3.9.6-3.1
Distribution: frozen unstable
Urgency: low
Maintainer: Wichert Akkerman <wakkerma@debian.org>
Description:
mtools - Tools for manipulating MSDOS files
Closes: 57867
Changes:
mtools (3.9.6-3.1) frozen unstable; urgency=low
.
* Non-maintainer upload to fix security problems
* set sysconfdir to /etc instead of /usr/etc
* Apply patch from Colin Phipps <crp22@cam.ac.uk>:
+ floppyd didn't call initgroups
+ symlink attack in lock-test in floppyd
+ lock-file in floppy was world-readable, exposing the X authority
+ partially Closes: Bug#57867
The DoS against floppyd is still possible, and should be fixed.
Files:
a9511148cf9f6172d817ffb38c3160fe 565 otherosfs standard mtools_3.9.6-3.1.dsc
d973040bdf9d136ff0e44287f0ee11aa 6339 otherosfs standard mtools_3.9.6-3.1.diff.gz
77d1da0a0da3f4543e023cf3a7aeaf49 183462 otherosfs standard mtools_3.9.6-3.1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iEYEARECAAYFAjiwB2YACgkQPLiSUC+jvC1b7ACgqpB6hyHBzOiSFvw1SJue5iPp
tKgAnjT+xj4SDxbW0KL4TOLZJ9nk8K42
=BbHE
-----END PGP SIGNATURE-----
Reply to: