Re: download.pl lets arbitrary stuff through

2006-12-11 Thread Stefan Scheler
> Fixed and uploaded, see #402631. Erm, do you this is a good fix? You're only checking the length! -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: download.pl lets arbitrary stuff through

2006-12-11 Thread Stefan Scheler
> Please provide a demonstration attack that would force users into > downloading, and wrongly checking, a malicious package. The only way that can > happen is if a mirror is already compromised, and that's why whe have > per-signature GPG releases for the archive [1]. Verification of signatures i