Re: [SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution

2008-01-17 Thread Steve Kemp
On Thu Jan 17, 2008 at 16:35:47 +0100, Philipp Kern wrote: > Still that breaks because os is not imported. Please fix. Quickly. Done. Steve -- # The Debian Security Audit Project. http://www.debian.org/security/audit -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsub

Re: [SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution

2008-01-17 Thread Philipp Kern
On Thu, Jan 17, 2008 at 02:38:45PM +, Steve Kemp wrote: > Felipe Sateler discovered that apt-listchanges, a package change history > notification tool, used unsafe paths when importing its python libraries. > This could allow the execution of arbitary shell commands if the root user > executed