Bug#605155: gquilt: Use of PYTHONPATH env var in an insecure way

2010-12-02 Thread Christine Spang
On Thu, Dec 02, 2010 at 02:52:26PM +1000, Peter Williams wrote: > A heads up. I'm currently working on a major upgrade to gquilt. Do you > need me to tell me when I do the release? That would be great! Generally I get somehow notified by Debian's upstream-watching scripts, but an extra reminde

Bug#605155: gquilt: Use of PYTHONPATH env var in an insecure way

2010-12-01 Thread Sandro Tosi
Hi Christine, On Thu, Dec 2, 2010 at 04:22, Christine Spang wrote: > It looks like gquilt doesn't actually require PYTHONPATH to > be set, anyway, since python already adds the directory of > the executed script to sys.path. I propose the following > patch: That patch seems ok. Cheers, -- Sand

Bug#605155: gquilt: Use of PYTHONPATH env var in an insecure way

2010-12-01 Thread Peter Williams
On 02/12/10 13:22, Christine Spang wrote: Hi all, Since we are currently in deep freeze for Squeeze, I'm very hesitant to ask the release managers to make an exception for a new release. (I wish I'd known that the new release fixed important bugs! I glanced at the changelog but it seemed like it

Bug#605155: gquilt: Use of PYTHONPATH env var in an insecure way

2010-12-01 Thread Christine Spang
Hi all, Since we are currently in deep freeze for Squeeze, I'm very hesitant to ask the release managers to make an exception for a new release. (I wish I'd known that the new release fixed important bugs! I glanced at the changelog but it seemed like it was all trivial or irrelevant-for-Debian th

Bug#605155: gquilt: Use of PYTHONPATH env var in an insecure way

2010-11-28 Thread Sandro Tosi
found 605155 0.20-2 0.22-1 tags 605155 fixed-upstream thanks Hi Peter On Sun, Nov 28, 2010 at 01:11, Peter Williams wrote: > Please update to gquilt-0.24 (released about 7 weeks ago) as the above > problem is no longer present in the code. Thanks for letting us know! Cheers, -- Sandro Tosi (a