Bug#521107: unsafe /tmp usage

2009-05-14 Thread Julien Cristau
On Fri, Apr 3, 2009 at 23:55:25 +0200, Moritz Muehlenhoff wrote: > This appears to be a re-introduction of the fix from xfs 1:1.0.4-2? > Not really, it was an incomplete fix. Cheers, Julien -- To UNSUBSCRIBE, email to debian-x-requ...@lists.debian.org with a subject of "unsubscribe". Troubl

Bug#521107: unsafe /tmp usage

2009-04-03 Thread Moritz Muehlenhoff
On Tue, Mar 24, 2009 at 02:50:25PM -0700, Kees Cook wrote: > Package: xfs > Version: 1:1.0.8-2.1 > Severity: normal > Tags: security > User: ubuntu-de...@lists.ubuntu.com > Usertags: origin-ubuntu jaunty > > Hello, > > There is a bug in the Ubuntu bug tracker about xfs's init script being used >

Bug#521107: unsafe /tmp usage

2009-03-25 Thread Kees Cook
On Wed, Mar 25, 2009 at 02:03:14PM +0100, Julien Cristau wrote: > Do we want to keep shipping xfs in squeeze? What are its use cases > these days? I think there may be things like LTSP that use it (where client-side fonts aren't much fun). However, I'm not entirely certain since I stopped using

Bug#521107: unsafe /tmp usage

2009-03-25 Thread Julien Cristau
On Tue, 2009-03-24 at 14:50 -0700, Kees Cook wrote: > There is a bug in the Ubuntu bug tracker about xfs's init script being used > in an unsafe fashion. It seems that OpenSUSE has solved this as well: > > "set_up_socket_dir moves /tmp/.font-unix to /tmp/.font-unix.$$. > Unfortunately $$ is predi

Bug#521107: unsafe /tmp usage

2009-03-24 Thread Kees Cook
Package: xfs Version: 1:1.0.8-2.1 Severity: normal Tags: security User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu jaunty Hello, There is a bug in the Ubuntu bug tracker about xfs's init script being used in an unsafe fashion. It seems that OpenSUSE has solved this as well: "set_up_s