Bug#682590: patch

2013-04-13 Thread Stefanos Harhalakis
Gr. It's never easy... I'll try to find a solution but I don't promise anything. "Adam D. Barratt" wrote: >On Sat, 2013-04-13 at 23:03 +0100, Stefanos Harhalakis wrote: >> And in case it helps more, here's the full patch. > >The upstream bug to which this bug is marked as forwarded indicate

Bug#682590: patch

2013-04-13 Thread Adam D. Barratt
On Sat, 2013-04-13 at 23:03 +0100, Stefanos Harhalakis wrote: > And in case it helps more, here's the full patch. The upstream bug to which this bug is marked as forwarded indicates that simply updating the expression to include "/" (as per your suggested patch) would reintroduce CVE-2012-3867, wh

Bug#682590: patch

2013-04-13 Thread Stefanos Harhalakis
And in case it helps more, here's the full patch. diff -Nur puppet-2.7.18.orig/lib/puppet/ssl/base.rb puppet-2.7.18/lib/puppet/ssl/base.rb --- puppet-2.7.18.orig/lib/puppet/ssl/base.rb 2012-07-10 00:36:29.0 +0100 +++ puppet-2.7.18/lib/puppet/ssl/base.rb 2013-04-13 23:01:44.245916200 +0100 @