Re: Bug#480972: vulnerable to symlink attacks

2008-05-21 Thread Sune Vuorela
On Thursday 22 May 2008, Nico Golde wrote: > Yes, same here. Looks like some deprecated package for kde > libs. I couldn't find that either in current source > packages. Marco, where did you get this information? Marco told me he got it from google code search. /Sune -- Man, do you know how cou

Re: Bug#480972: vulnerable to symlink attacks

2008-05-21 Thread Nico Golde
Hi Sune, * Sune Vuorela <[EMAIL PROTECTED]> [2008-05-18 21:35]: > On Tuesday 13 May 2008, Marco d'Itri wrote: > > Security team: libuu-dev is a static-only library (see #216593). > > klibido, nget and slrn build-depend on libuu-dev, while > > libconvert-uulib-perl and kde (I don't know exactly whic

Re: Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Sune Vuorela
On Tuesday 13 May 2008, Marco d'Itri wrote: > Security team: libuu-dev is a static-only library (see #216593). > klibido, nget and slrn build-depend on libuu-dev, while > libconvert-uulib-perl and kde (I don't know exactly which package, > look in the kdesupport directory) contain an embedded copy

Bug#480972: vulnerable to symlink attacks

2008-05-13 Thread Marco d'Itri
Please find out which part of KDE embeds this code... - Forwarded message from Marco d'Itri <[EMAIL PROTECTED]> - Subject: Bug#480972: vulnerable to symlink attacks Reply-To: Marco d'Itri <[EMAIL PROTECTED]>, [EMAIL PROTECTED] From: Marco d'Itri <[EM