Bug#447344: CVE-2007-5200 insecure tmp file handling

2007-10-25 Thread Nico Golde
Hi, uploading an NMU now with permission of the maintainer. Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpxun3eDGAFj.pgp Description: PGP signature

Bug#447344: CVE-2007-5200 insecure tmp file handling

2007-10-24 Thread Nico Golde
Hi, I intent do NMU this package to fix the vulnerability. Attached is a patch for an NMU. It will be also archived on: http://people.debian.org/~nion/nmu-diff/hugin-0.6.1-1_0.6.1-1.1.patch Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security r

Bug#447344: CVE-2007-5200 insecure tmp file handling

2007-10-20 Thread Nico Golde
Package: hugin Version: 0.6.1-1 Severity: important Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for hugin. CVE-2007-5200[0]: | hugin in SUSE openSUSE 10.2 and 10.3 allows local users to overwrite | arbitrary files via a symlink attack on a temp