Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling

2008-11-04 Thread Matthias Wandel
Ok, I changed the mkstemp back to mktemp. Sorry about that. Matthias - Original Message - From: "Bruno De Fraine" <[EMAIL PROTECTED]> To: "Matthias Wandel" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Tuesday, November 04, 2008 5:13 AM Subject

Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling

2008-11-04 Thread Matthias Wandel
TECTED]> To: "Matthias Wandel" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Tuesday, November 04, 2008 5:13 AM Subject: Re: Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling Hello Matthias, On 3-nov-08, at 16:0

Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling

2008-11-03 Thread Matthias Wandel
Ok, I have integrated this patch, plus a temp file patch that was submitted, and uploaded it as the head rev copy on the website. The head rev version number has been changed to 2.85. I have made sure it works under Windows, and done some quick checks under Linux. Let me know if its good for you

Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling

2008-10-29 Thread Matthias Wandel
Ah, now I remember. That's why I didn't change it, especially because the rest of jhead just layers on top of the "jhead -cmd" functionality. Matthias - Original Message - From: "Bruno De Fraine" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Wednesday, Oct