Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496377 normal thanks Another false positive. file: /usr/lib/lazarus/tools/install/create_lazarus_export_tgz.sh This script does: if [ "x$Download" = "xyes" ]; then echo "downloading lazarus svn ..." cd /tmp rm -rf /tmp/lazarus svn export http://svn.freepascal.org/svn/lazaru

Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Christoph Donges
unsubscribe On Mon, Aug 25, 2008 at 5:48 AM, Torsten Werner <[EMAIL PROTECTED] > wrote: > Hi Mazen, > > > On Sun, Aug 24, 2008 at 8:05 PM, Dmitry E. Oboukhov <[EMAIL PROTECTED]> wrote: > > In some packages I've discovered scripts with errors which may be used > > by a user for damaging important

Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Torsten Werner
Hi Mazen, On Sun, Aug 24, 2008 at 8:05 PM, Dmitry E. Oboukhov <[EMAIL PROTECTED]> wrote: > In some packages I've discovered scripts with errors which may be used > by a user for damaging important system files or user's files. That should be fixed upstream. I'll check all files matching *.sh and

Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dmitry E. Oboukhov
Package: lazarus-src Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts of packages (marked as executable) were tested. In some packages I've discovered scripts with errors