Re: zoo: directory traversal security bug

2005-07-18 Thread Jose Carlos do Nascimento
Hi, Nigel finally one good answer :) I tried to find upstream author of zoo,, but I didnt find his email. I know a little bit of C, and my Boss know C very well, them, I will try to solve this problem with him. Thanks [] Jose Carlos On 14/07/05, Jose Carlos do Nascimento <[EMAIL PROTECT

Re: zoo: directory traversal security bug

2005-07-15 Thread skaller
On Fri, 2005-07-15 at 19:23 -0700, Michael K. Edwards wrote: > On 7/15/05, skaller <[EMAIL PROTECTED]> wrote: > > Oh .. which DD can be responsible for my package Felix then? > > They would have to know: > > > > * C/C++ > > * OCaml > > * Python > > * Bash > > * Interscript > > * Felix > > * ocamll

Re: zoo: directory traversal security bug

2005-07-15 Thread Michael K. Edwards
On 7/15/05, skaller <[EMAIL PROTECTED]> wrote: > Oh .. which DD can be responsible for my package Felix then? > They would have to know: > > * C/C++ > * OCaml > * Python > * Bash > * Interscript > * Felix > * ocamllex/ocamlyacc and Elkhound > * HTML/XML > * Latex/troff/texinfo > * snippets of 10 o

Re: zoo: directory traversal security bug

2005-07-15 Thread skaller
On Fri, 2005-07-15 at 06:53 -0700, Richard A. Hecker wrote: > That is true, but we do have an obligation to our users. Every DD makes > mistakes. What is the > chance they might upload something that contains a Trojan if they do not > know the source? How > would they be able to check a claim

Re: zoo: directory traversal security bug

2005-07-15 Thread Nigel Jones
On 14/07/05, Jose Carlos do Nascimento <[EMAIL PROTECTED]> wrote: > Hi, All > > I'm mantainer of zoo package and I need help to solve this bug: > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=309594 Have you considered looking at how gzip, zip, unzip, tar, ... handle this stuff? You may be ab

Re: zoo: directory traversal security bug

2005-07-15 Thread Manoj Srivastava
On Fri, 15 Jul 2005 01:20:44 +0200, Bartosz Fenski aka fEnIo <[EMAIL PROTECTED]> said: > On Fri, Jul 15, 2005 at 12:10:50AM +0100, Roger Leigh wrote: >> If you can't understand what you are packaging, you shouldn't be >> packaging it, IMHO. > So maybe our documentation should state that?

Re: zoo: directory traversal security bug

2005-07-15 Thread Richard A. Hecker
Oleksandr Moskalenko wrote: Having a good relationship with upstream helps immensely especially if the maintainer doesn't know C or C++ or whatever the software is written in. Maybe that should be in the policy, too ;) We really should not take it to the absurd extremes. That is true, but w

Re: zoo: directory traversal security bug

2005-07-15 Thread Jose Carlos do Nascimento
Like Alex, I think if one program has problem, we need to solve this problem against upstream author. Because he know his program and know how to solve bugs, etc. I too think like Bartosz Fenski, but with one difference. "if you're going to package something written in Python it is REQUIRE

Re: zoo: directory traversal security bug

2005-07-14 Thread Oleksandr Moskalenko
* Bartosz Fenski aka fEnIo <[EMAIL PROTECTED]> [2005-07-15 01:20:44 +0200]: > On Fri, Jul 15, 2005 at 12:10:50AM +0100, Roger Leigh wrote: > > If you can't understand what you are packaging, you shouldn't be > > packaging it, IMHO. > > So maybe our documentation should state that? > > I mean som

Re: zoo: directory traversal security bug

2005-07-14 Thread Bartosz Fenski aka fEnIo
On Fri, Jul 15, 2005 at 12:10:50AM +0100, Roger Leigh wrote: > If you can't understand what you are packaging, you shouldn't be > packaging it, IMHO. So maybe our documentation should state that? I mean something like "if your're going to package something written in Python it is highly recommend

Re: zoo: directory traversal security bug

2005-07-14 Thread Roger Leigh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Jose Carlos do Nascimento <[EMAIL PROTECTED]> writes: > I thought to be a mantainer I just must know debian-policy, how to > create Debian package,, how to create docs,etc . > I read many Debian Docs, and I didnt read anything about people must > be

Re: zoo: directory traversal security bug

2005-07-14 Thread Thomas Viehmann
Jose Carlos do Nascimento wrote: >> I do prefer people knowing what it actually is they're putting into the >> archive. > I thought to be a mantainer I just must know debian-policy, how to > create Debian package,, how to create docs,etc . > I read many Debian Docs, and I didnt read anything abou

Re: zoo: directory traversal security bug

2005-07-14 Thread Jose Carlos do Nascimento
I thought to be a mantainer I just must know debian-policy, how to create Debian package,, how to create docs,etc . I read many Debian Docs, and I didnt read anything about people must be C, python, php ,etc developer. [] Jose Carlos Ganesan Rajagopal wrote: Not to me. I don't think

Re: zoo: directory traversal security bug

2005-07-14 Thread Thomas Viehmann
Ganesan Rajagopal wrote: > Not to me. I don't think it's a requirement to know C to maintain a > package. Well, how about if the package's source is 1 lines of C code? I do prefer people knowing what it actually is they're putting into the archive. Kind regards T. -- Thomas Viehmann, http:/

Re: zoo: directory traversal security bug

2005-07-13 Thread Ganesan Rajagopal
> "Thomas" == Thomas Viehmann <[EMAIL PROTECTED]> writes: > Jose Carlos do Nascimento wrote: >> I'm mantainer of zoo package and I need help to solve this bug: > ... >> I dont know C :( > Is it just me or does this sound wrong? Not to me. I don't think it's a requirement to know C to mainta

Re: zoo: directory traversal security bug

2005-07-13 Thread Jose Carlos do Nascimento
Hi, Thomas Jose Carlos do Nascimento wrote: I'm mantainer of zoo package and I need help to solve this bug: I adopted this package some days ago :) I know to make a package .deb,, but I am not a C developer :) I tried to find one solution in zoo packages from others distribs, but an

Re: zoo: directory traversal security bug

2005-07-13 Thread Thomas Viehmann
Jose Carlos do Nascimento wrote: > I'm mantainer of zoo package and I need help to solve this bug: ... > I dont know C :( Is it just me or does this sound wrong? Kind regards T. -- Thomas Viehmann, http://thomas.viehmann.net/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

zoo: directory traversal security bug

2005-07-13 Thread Jose Carlos do Nascimento
Hi, All I'm mantainer of zoo package and I need help to solve this bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=309594 I dont know C :( I would be very grateful if someone could help me. Thanks Jose Carlos -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe