Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 06:44:57PM -0700, Russ Allbery wrote: > Steve Langasek <[EMAIL PROTECTED]> writes: > > The example *is* wrong - the example given is never safe to run, because > > the only way to verify beforehand that /tmp/zenity is not a symlink to > > something more important is by firs

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Peter Samuelson
[Neil Williams] > $ pilot-qof -x data.xml --invoice-city -t 2006-11-08 | dfxml-invoice - \ > | zenity --text-info --title="2006-11-08" - > > 2. Unnecessarily complicated for documentation (the need for '\' is, > IMHO, an indication that the command is too long). Not to disagree with your real t

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Russ Allbery
Steve Langasek <[EMAIL PROTECTED]> writes: > The example *is* wrong - the example given is never safe to run, because > the only way to verify beforehand that /tmp/zenity is not a symlink to > something more important is by first explicitly *creating* your file > funder /tmp (non-destructively), t

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > Yes, a race condition could happen and yes, there could be all sorts of > complicated ways of handling temp files and passing back the name of the > file but examples have to be simple and clear, not obfuscated by > problems unrelated to the nature of the

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Neil Williams
On Sun, 2008-08-24 at 13:30 -0700, Steve Langasek wrote: > On Sun, Aug 24, 2008 at 08:28:32PM +0100, Neil Williams wrote: > > =head1 > > A more complex example using 'zenity' - a Gnome dialog generator. > > > $ pilot-qof -x data.xml --invoice-city -t 2006-11-08 | dfxml-invoice - > > > /tmp/zenity

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 08:28:32PM +0100, Neil Williams wrote: > > For example if a script uses in its work a temp file which is created > > in /tmp directory, then every user can create symlink with the same > > name in this directory in order to destroy or rewrite some system > > or user

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: > Package: initramfs-tools > Severity: grave > This message about the error concerns a few packages at once. I've > tested all the packages (for Lenny) on my Debian mirror. All scripts > of packages (marked as executable) we

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Neil Williams
On Sun, 2008-08-24 at 22:05 +0400, Dmitry E. Oboukhov wrote: > Package: datafreedom-perl > Severity: grave No, that is just plain wrong, sorry. > Hi, maintainer! (and I do so hate unnecessary exclamation marks) > This message about the error concerns a few packages at once. I've > tested al

Re: dhclient-script, hooks, and changing the environment

2008-08-24 Thread martin f krafft
also sprach Daniel Bayer <[EMAIL PROTECTED]> [2008.08.23.2000 +0100]: > I used hooks, which mangled the environment in such a way that the > default route was not set but instead a host route to my openvpn > server via the announced default gateway. Including a simple detection > if I'm home or not

Re: Hardware compatibility test: draft proposal

2008-08-24 Thread Wouter Verhelst
On Fri, Aug 22, 2008 at 11:05:49AM +0100, Chris Lamb wrote: > Wouter Verhelst wrote: > > > As I mentioned in my blog[1], I kindof like the suggestion that Bdale > > came up with during Debconf that we write a hardware compatibility test > > of sorts that hardware vendors could run on their own har

Re: 1 of 400 dpkg databases corrupt?

2008-08-24 Thread Wouter Verhelst
On Sat, Aug 23, 2008 at 09:13:42AM +0200, Petter Reinholdtsen wrote: > [Russ Allbery] > > It's not *impossible*... someone could be running the scripts from the > > package without having the package installed. I don't know why they'd do > > that, though, or whether that's a more plausible explana

Re: Debian marketing team

2008-08-24 Thread Henning Sprang
Hi Andreas, As response to your post from some while ago: Andreas Schuldei wrote: * It would be good to collect Debian related News centrally (wiki) and depending on its content and impact spread them locally or globally. For collection(plus commenting, tagging, and saving of snapshots!

Re: Minor bobble in etch->lenny upgrade

2008-08-24 Thread Vincent Danjean
Paul Wise wrote: > On Sun, Aug 24, 2008 at 1:00 AM, Steve Greenland <[EMAIL PROTECTED]> wrote: > >> Just upgraded an old etch box to lenny via aptitude, ran into the >> following minor problem: >> >> (Reading database ... 22081 files and directories currently installed.) >> Preparing to replace mo

Re: Bug#496326: ITP: gwibber -- open source microblogging client for GNOME

2008-08-24 Thread Julien Cristau
On Sun, Aug 24, 2008 at 14:39:08 +0100, Daniel Watkins wrote: > Description : open source microblogging client for GNOME > Please remove 'open source' from the short description, that's not adding any information. Cheers, Julien -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subje

Bug#496335: ITP: python-validate -- Python library to check specification conformance

2008-08-24 Thread Daniel Watkins
Package: wnpp Severity: wishlist Owner: Daniel Watkins <[EMAIL PROTECTED]> Currently a version of python-validate is shipped with configobj. I'd like to package it separately as per policy. * Package name: python-validate Version : 0.3.2 Upstream Author : Michael Foord <[EMAIL P

Bug#496326: ITP: gwibber -- open source microblogging client for GNOME

2008-08-24 Thread Daniel Watkins
Package: wnpp Severity: wishlist Owner: Daniel Watkins <[EMAIL PROTECTED]> * Package name: gwibber Version : 0~bzr98 Upstream Author : Ryan Paul <[EMAIL PROTECTED]> * URL : https://launchpad.net/gwibber * License : GPL Programming Lang: Python Description

Bug#496321: ITP: blocks-of-the-undead -- Tetris Attack clone with spooky undertones

2008-08-24 Thread Evgeni Golov
X-Debbugs-Cc: [EMAIL PROTECTED], debian-devel@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Games Team <[EMAIL PROTECTED]> * Package name: blocks-of-the-undead Version : 1.0 Upstream Author : Jared Luxenberg, Justin Lokey, Korina Loumidi, Keith Bare * URL

Re: Bug#481134: libpoppler does not use cmap files from xpdf-{japanese,...}, and fails to parse Japanese PDF files.

2008-08-24 Thread Loïc Minier
On Sun, Aug 24, 2008, Osamu Aoki wrote: > But current dependency definition does not provide this path... > libpoppler3 should "Suggests: poppler-data". (I vaguely think we can not > do "Recommends:" here due to policy.) Wont help much I'm afraid; people wont have a clue that they should be chec

Re: Bug#481134: libpoppler does not use cmap files from xpdf-{japanese,...}, and fails to parse Japanese PDF files.

2008-08-24 Thread Osamu Aoki
Hi, On Sat, Aug 23, 2008 at 11:58:07AM -0700, Junichi Uekawa wrote: > From the user's perspective, we probably want some > kind of documentation, since nothing pulls in poppler-data; users > expect working evince but they will be broken on upgrade until they > install poppler-data. But current de