Hi Felipe, * Felipe Augusto van de Wiel (faw) <[EMAIL PROTECTED]> [2008-02-06 18:26]: > On 04-02-2008 10:16, Nico Golde wrote: > > * Frank Lichtenheld <[EMAIL PROTECTED]> [2008-02-04 12:56]: [...] > >> $tmpdir = $ENV{'TMPDIR'} || '/tmp'; > >> $tmpfile = $tmpdir . "/ipp.$$.tmp"; > >> unlink($tmpfile); > >> $tmp = new IO::File; > >> $tmp->open(">$tmpfile") || error("cannot write into $tmpfile: $!"); > > [...] > > > > Thanks I confirmed this, a CVE id is pending.
I tried to catch you up in #debian-security but you didn't join for some days :) > Just for the record, there is a new version of wml that > should be packaged, I will take care to properly keep this fix > if it is not present upstream. Would you like me to prepare a > package to fix this? Or should I wait for Debian Security Team? > I'm OK with a NMU. If you can upload a fix before tomorrow do it, otherwise I'll take care of this tomorrow. > As soon as possible, I will work on the new package and > also to clean up the BTS for wml. Sorry for the delay. No problem :) Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.
pgp93hW7mKBVY.pgp
Description: PGP signature