Bug#783605: dpkg-sig --verify does not fail unless the .deb is signed

2015-04-28 Thread Paul Harvey
Subject: dpkg-sig --verify does not fail unless the .deb is signed Package: dpkg-sig Version: 0.13.1+nmu2 Severity: grave Tags: security, patch Dear Maintainer, Perhaps I've misunderstood the purpose of this tool, but one may have hoped for something that would check that a .deb was signed with a

Bug#695224: perl-modules: Locale::Maketext code injection

2013-03-30 Thread Paul Harvey
Thanks Dominic for your pragmatic feedback, On 30/03/13 01:23, Dominic Hargreaves wrote: On Mon, Mar 25, 2013 at 02:00:03PM +1100, Paul Harvey wrote: consider carefully before use. If the caller can't trust the API version being reported, what is the point of version numbers in the first

Bug#695224: perl-modules: Locale::Maketext code injection

2013-03-24 Thread Paul Harvey
Paul, Sorry for the delay in responding to this... On Mon, Mar 11, 2013 at 02:37:31PM +1100, Paul Harvey wrote: Hi there, On Fri, Jan 18, 2013 at 03:06:38PM +, Dominic Hargreaves wrote: ... Debian stable. As such I'd be very interested in hearing from anyone who has real world examples

Bug#695224: perl-modules: Locale::Maketext code injection

2013-03-10 Thread Paul Harvey
t 1.23 proper. Here's the changelog, FWIW http://cpansearch.perl.org/src/TODDR/Locale-Maketext-1.23/ChangeLog Cheers -- Paul Harvey Foswiki developer -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org