Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Rob Browning
Helmut Grohne writes: > On Sat, Jan 19, 2013 at 10:51:23AM -0600, Rob Browning wrote: >> Assuming I understood the situation correctly, this might be a plausible >> fix: > > Yes. Thanks for your quick reaction. You're certainly welcome, though it was just luck -- happened to be poking around the

Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Helmut Grohne
On Sat, Jan 19, 2013 at 10:51:23AM -0600, Rob Browning wrote: > Assuming I understood the situation correctly, this might be a plausible > fix: Yes. Thanks for your quick reaction. Helmut -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Troub

Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Rob Browning
tag 698490 +patch thanks Assuming I understood the situation correctly, this might be a plausible fix: >From 679c67c615947b44aafa969f00ea00f9ed997e4e Mon Sep 17 00:00:00 2001 From: Rob Browning Date: Sat, 19 Jan 2013 10:44:34 -0600 Subject: [PATCH 1/1] Create git-effort temp file via mktemp and

Bug#698490: git-effort: predictable /tmp filename

2013-01-19 Thread Helmut Grohne
Package: git-extras Version: 1.7.0-1.1 Severity: serious Tags: security The git-effort utility uses /tmp/.git-effort as the name of its temporary filename. While this already prevents two users from using this utility (due to not cleaning its temporary file) it also allows for targeted symbolic l