Bug#775681: multiple /tmp file vulnerabilities

2015-01-28 Thread Victor Seva
On 01/25/2015 09:52 PM, Helmut Grohne wrote: > On Sat, Jan 24, 2015 at 02:30:37PM +0100, Victor Seva wrote: >> On 01/18/2015 05:16 PM, Helmut Grohne wrote: [snip] > All of these fixes are appropriate for a Debian Security Advisory. Thus > they should also be appropriate for a freeze unblock. Please

Bug#775681: multiple /tmp file vulnerabilities

2015-01-25 Thread Helmut Grohne
Control: severity -1 serious Hi Victor, Thank you very much for investing your time in addressing these issues! On Sat, Jan 24, 2015 at 02:30:37PM +0100, Victor Seva wrote: > On 01/18/2015 05:16 PM, Helmut Grohne wrote: > > Granted, some of the results are examples, documentation or obsolete. >

Bug#775681: multiple /tmp file vulnerabilities

2015-01-24 Thread Victor Seva
On 01/18/2015 05:16 PM, Helmut Grohne wrote: > Granted, some of the results are examples, documentation or obsolete. > But quite a few reach the default settings: > > * kamcmd defaults to connecting to unixs:/tmp/kamailio_ctl. - added default_ctl.patch. ctl defaults to /var/run/kamailio/kamail

Bug#775681: multiple /tmp file vulnerabilities

2015-01-20 Thread Victor Seva
forwarded 775681 https://github.com/kamailio/kamailio/issues/48 thanks -- I opened a dialog with upstream about the issue and I will change the example settings in the package in the next upload Thanks for the report, Victor Seva signature.asc Description: OpenPGP digital signature

Bug#775681: multiple /tmp file vulnerabilities

2015-01-18 Thread Helmut Grohne
Package: kamailio Version: 4.2.0-1.1 Severity: important Tags: security The kamailio package now installs /etc/kamailio/kamailio-basic.cfg which can be selected via the CFGFILE= setting in /etc/default/kamailio. The configuration contains: modparam("mi_fifo", "fifo_name", "/tmp/kamailio_fifo") T