Bug#605178: python-uno: Use of PYTHONPATH env var in an insecure way

2010-12-02 Thread Rene Engelhard
On Thu, Dec 02, 2010 at 10:47:55PM +0100, Sandro Tosi wrote: > yeah, sorry about that: the submits were done with mass-bug, but the > tool is affected by a bug (#605235) that generated 3 identical reports > instead of 3 for different versions (1:2.4.1+dfsg-1+lenny8 1:3.2.1-7, > 1:3.3.0~beta2-2) Ah

Bug#605178: python-uno: Use of PYTHONPATH env var in an insecure way

2010-12-02 Thread Sandro Tosi
Hi Rene, On Sun, Nov 28, 2010 at 00:29, Rene Engelhard wrote: > found 605178 1:3.2.1-7 > found 605178 1:2.4.1+dfsg-1+lenny8 > severity 605178 minor > thanks > > On Sat, Nov 27, 2010 at 10:45:58PM +, Sandro Tosi wrote: >> Version: 1:3.3.0~beta2-2 > > If the log says 2.4.1 and 3.2.1, too, why d

Bug#605178: python-uno: Use of PYTHONPATH env var in an insecure way

2010-11-27 Thread Rene Engelhard
found 605178 1:3.2.1-7 found 605178 1:2.4.1+dfsg-1+lenny8 severity 605178 minor thanks On Sat, Nov 27, 2010 at 10:45:58PM +, Sandro Tosi wrote: > Version: 1:3.3.0~beta2-2 If the log says 2.4.1 and 3.2.1, too, why did you file it only against 1:3.3.0~beta2-2? :) > Severity: important Well, i

Processed: Re: Bug#605178: python-uno: Use of PYTHONPATH env var in an insecure way

2010-11-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 605178 1:3.2.1-7 Bug #605178 [python-uno] python-uno: Use of PYTHONPATH env var in an insecure way Bug #605181 [python-uno] python-uno: Use of PYTHONPATH env var in an insecure way Bug #605193 [python-uno] python-uno: Use of PYTHONPATH env

Bug#605178: python-uno: Use of PYTHONPATH env var in an insecure way

2010-11-27 Thread Sandro Tosi
Package: python-uno Version: 1:3.3.0~beta2-2 Severity: important Tags: security User: debian-pyt...@lists.debian.org Usertags: pythonpath Jakub Wilk performed an analysis[1] for packages setting PYTHONPATH in an insecure way. Those packages do something like: PYTHONPATH=/spam/eggs:$PYTHONPATH