Bug#605150: mmass: Use of PYTHONPATH env var in an insecure way

2010-11-30 Thread Moritz Muehlenhoff
On Mon, Nov 29, 2010 at 07:36:12PM +0100, Moritz Muehlenhoff wrote: > mmass maintainers, you still still a fix for Squeeze, please get in > contact with the release managers for a targeted tpu fix. Squeeze is fine, PYTHONPATH isn't used in this version. Cheers, Moritz -- To UNSUBSCRIB

Bug#605150: mmass: Use of PYTHONPATH env var in an insecure way

2010-11-27 Thread Sandro Tosi
Package: mmass Version: 3.8.0-1 Severity: grave Tags: security User: debian-pyt...@lists.debian.org Usertags: pythonpath Jakub Wilk performed an analysis[1] for packages setting PYTHONPATH in an insecure way. Those packages do something like: PYTHONPATH=/spam/eggs:$PYTHONPATH This is wrong,