Here is the diff. Built and tested. diff --git a/debian/changelog b/debian/changelog index b2e88d5..16d0e66 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,10 @@ +bristol (0.60.5-3) unstable; urgency=low + + * Exporting unmodified PATH is unnecessary. Drop + /usr/share/bristol/lib from the LD_LIBRARY_PATH. + + -- Alessio Treglia <ales...@debian.org> Thu, 14 Oct 2010 12:55:41 +0200 + bristol (0.60.5-2) unstable; urgency=high
* Add patch to solve security issue CVE-2010-3351: diff --git a/debian/patches/90-CVE_insecure_library_loading.patch b/debian/patches/90-CVE_insecure_library_loading.patch index a6fc40e..7fc156d 100644 --- a/debian/patches/90-CVE_insecure_library_loading.patch +++ b/debian/patches/90-CVE_insecure_library_loading.patch @@ -2,17 +2,19 @@ Subject: Fix insecure library loading - CVE-2010-3351. Origin: upstream, https://sourceforge.net/support/tracker.php?aid=3077160 Bug-Debian: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598285 --- - bin/startBristol.in | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) + bin/startBristol.in | 4 +--- + 1 file changed, 1 insertion(+), 3 deletions(-) --- bristol.orig/bin/startBristol.in +++ bristol/bin/startBristol.in -@@ -347,7 +347,7 @@ fi +@@ -347,9 +347,7 @@ fi export SLAB_HOME=$BRISTOL export BRIGHTON=$BRISTOL -export LD_LIBRARY_PATH=/usr/local/lib:usr/lib:${LD_LIBRARY_PATH}:${BRISTOL}/lib -+export ld_library_pa...@bristol_dir@/lib:/usr/local/lib:/usr/lib:/lib - - export PATH=${PATH}:$BRISTOL/bin:/usr/local/bin +- +-export PATH=${PATH}:$BRISTOL/bin:/usr/local/bin ++export LD_LIBRARY_PATH=/usr/local/lib:/usr/lib:/lib + if [ $jack -eq 1 ]; then + ldd `which bristol` | grep jack > /dev/null 2>&1 -- Alessio Treglia <ales...@debian.org> Debian & Ubuntu Developer | Homepage: http://www.alessiotreglia.com 0FEC 59A5 E18E E04F 6D40 593B 45D4 8C7C DCFC 3FD0 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org