Hi Felipe,
* Felipe Augusto van de Wiel (faw) <[EMAIL PROTECTED]> [2008-02-06 18:26]:
> On 04-02-2008 10:16, Nico Golde wrote:
> > * Frank Lichtenheld <[EMAIL PROTECTED]> [2008-02-04 12:56]:
[...] 
> >> $tmpdir = $ENV{'TMPDIR'} || '/tmp';
> >> $tmpfile = $tmpdir . "/ipp.$$.tmp";
> >> unlink($tmpfile);
> >> $tmp = new IO::File;
> >> $tmp->open(">$tmpfile") || error("cannot write into $tmpfile: $!");
> > [...] 
> > 
> > Thanks I confirmed this, a CVE id is pending.

I tried to catch you up in #debian-security but you didn't 
join for some days :)

>       Just for the record, there is a new version of wml that
> should be packaged, I will take care to properly keep this fix
> if it is not present upstream. Would you like me to prepare a
> package to fix this? Or should I wait for Debian Security Team?
> I'm OK with a NMU.

If you can upload a fix before tomorrow do it, otherwise 
I'll take care of this tomorrow.

>       As soon as possible, I will work on the new package and
> also to clean up the BTS for wml. Sorry for the delay.

No problem :)
Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgp93hW7mKBVY.pgp
Description: PGP signature

Reply via email to