Re: download.pl lets arbitrary stuff through

2006-12-11 Thread Stefan Scheler
> Please provide a demonstration attack that would force users into > downloading, and wrongly checking, a malicious package. The only way that can > happen is if a mirror is already compromised, and that's why whe have > per-signature GPG releases for the archive [1]. Verification of signatures i

Re: download.pl lets arbitrary stuff through

2006-12-11 Thread Javier Fernández-Sanguino Peña
On Mon, Dec 11, 2006 at 09:42:35PM +0100, Stefan Scheler wrote: > > Fixed and uploaded, see #402631. > > Erm, do you this is a good fix? You're only checking the length! Please provide a demonstration attack that would force users into downloading, and wrongly checking, a malicious package. The o

Re: download.pl lets arbitrary stuff through

2006-12-11 Thread Stefan Scheler
> Fixed and uploaded, see #402631. Erm, do you this is a good fix? You're only checking the length! -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: download.pl lets arbitrary stuff through

2006-12-11 Thread Javier Fernández-Sanguino Peña
On Mon, Dec 11, 2006 at 08:17:11PM +0100, Bernhard R. Link wrote: > I was just made aware, that > http://packages.debian.org/cgi-bin/download.pl > is very liberate in putting arbitrary stuff in the website, > try for example: > > http://packages.debian.org/cgi-bin/download.pl?arch=i386&file=";> h