Re: Bitten patch to release new version

2010-11-18 Thread anatoly techtonik
On Thu, Nov 18, 2010 at 8:28 PM, Sandro Tosi wrote: > On Thu, Nov 18, 2010 at 19:10, anatoly techtonik wrote: >> Here is the patch to release new beta version of Bitten. > > "here" where? :) Oops. Fixed. =) >> What is the further process to get this in Lenny backports? > > first you got to uplo

Re: Untrusted search path vulnerabilities

2010-11-18 Thread Chow Loong Jin
On Friday 19,November,2010 03:47 AM, Filippo Rusconi wrote: > Hello, Pythonistas, > > in my slow learning of Python and of Python program packaging, here am > I again asking for advice: > > On Wed, Nov 17, 2010 at 10:58:48PM +0100, Jakub Wilk wrote: >> A number of packages in the archive sets the

Re: Untrusted search path vulnerabilities

2010-11-18 Thread Filippo Rusconi
Hello, Pythonistas, in my slow learning of Python and of Python program packaging, here am I again asking for advice: On Wed, Nov 17, 2010 at 10:58:48PM +0100, Jakub Wilk wrote: > A number of packages in the archive sets the PYTHONPATH environment > variable in an insecure way. They do something

Re: Bitten patch to release new version

2010-11-18 Thread Sandro Tosi
On Thu, Nov 18, 2010 at 19:10, anatoly techtonik wrote: > Here is the patch to release new beta version of Bitten. "here" where? :) > What is the further process to get this in Lenny backports? first you got to upload to experimental (since a beta it's not the best version to have in unstable a

Bitten patch to release new version

2010-11-18 Thread anatoly techtonik
Hi, Here is the patch to release new beta version of Bitten. What is the further process to get this in Lenny backports? P.S. Check out instructions on using pbuilder with svn-buildpackage. http://wiki.debian.org/Teams/PythonAppsPackagingTeam/HowToPBuilder -- anatoly t. -- To UNSUBSCRIBE, emai

Re: Untrusted search path vulnerabilities

2010-11-18 Thread Mike Hommey
On Thu, Nov 18, 2010 at 07:04:07PM +0800, Paul Wise wrote: > > On Wed, Nov 17, 2010 at 22:58, Jakub Wilk wrote: > >> A number of packages in the archive sets the PYTHONPATH environment > >> variable > >> in an insecure way. They do something like: > >> > >>      PYTHONPATH=/spam/eggs:$PYTHONPATH

Re: Untrusted search path vulnerabilities

2010-11-18 Thread Paul Wise
> On Wed, Nov 17, 2010 at 22:58, Jakub Wilk wrote: >> A number of packages in the archive sets the PYTHONPATH environment variable >> in an insecure way. They do something like: >> >>      PYTHONPATH=/spam/eggs:$PYTHONPATH >> >> This is wrong, because if PYTHONPATH were originally unset or empty,

Re: Untrusted search path vulnerabilities

2010-11-18 Thread Sandro Tosi
Hi all, here below the mail Jakub sent to d-python yesterday, I'm bouncing it now to d-d now to wider spread and as a notification of an upcoming mbf (if no stop comes it's expected to happen this evening). Please follow the whole thread at [1] for further discussion (and keep d-p in the loop in ca

Re: Untrusted search path vulnerabilities

2010-11-18 Thread Sandro Tosi
Hi all, here below the mail Jakub sent to d-python yesterday, I'm bouncing it now to d-d now to wider spread and as a notification of an upcoming mbf (if no stop comes it's expected to happen this evening). Please follow the whole thread at [1] for further discussion (and keep d-p in the loop in ca