Note that modern versions of "patch" already do symlink protection.
I think this means you could drop this "-l" check in Patch.pm.
>From http://git.savannah.gnu.org/cgit/patch.git/tree/NEWS ...
Changes in version 2.7.5:
* There are users which expect patch to follow symbolic links in the workin
Package: dpkg
Version: 1.18.4ubuntu1.4
Severity: normal
scripts/Dpkg/Source/Patch.pm has the following code:
while (1) {
if (-l $path) {
error(g_('diff %s modifies file %s through a symlink: %s'),
$diff, $fn{$key}, $path);
}
$diff is a patch file
Fixed in
https://anonscm.debian.org/cgit/pkg-python-debian/python-debian.git/commit/setup.py.in?id=5a622c60232163faa0c0f7fddab405227419b616
The first tagged release to contain this change was v0.1.30.
Maintainers, would you please push this version to PyPI? The latest
version there is v0.1.28.
I've wanted to become a Debian packager for a while now, and I'm
interested in maintaining this package in Debian/Ubuntu. What is the
next step?
On Tue, Jan 5, 2016 at 9:34 PM, hp cre wrote:
> Hi,
> Forgive my ignorance guys, but why are you still discussing updating the
> firefly release in Jessie when ceph has released two major stable releases
> after it, one of them being an LTS (hammer)?
> Why not just propose to upgrade Jessie's pa
On Fri, Sep 11, 2015 at 4:04 AM, Gaudenz Steinlin wrote:
> I fail to see how this is a security issue.
Please see https://www.owasp.org/index.php/HTTP_Response_Splitting for
an explanation about HTTP header manipulation attacks.
- Ken
Package: mlocate
Version: 0.26-1ubuntu1
Severity: normal
Dear Maintainer,
Ceph is a software-defined storage project, and it stores its data in
/var/lib/ceph as a big set of files. The problem is that updatedb indexes
/var/lib/ceph along with everything else on the system. This /var/lib/ceph
loca
Can you please paste the output of klist 1) before running either
command, 2) after running with --verbose, and 3) after actually
succeeding?
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
8 matches
Mail list logo