Re: [BUGS] Insecure temporary file usage in developer/build tools

2005-01-24 Thread Tom Lane
Martin Pitt <[EMAIL PROTECTED]> writes: > Used in build, fixed for Debian (see attached patch): > postgresql-7.4.6/src/backend/catalog/genbki.sh > postgresql-7.4.6/src/test/bench/perquery AFAICS these were fixed some time ago in our CVS. regards, tom lane

[BUGS] Insecure temporary file usage in developer/build tools

2005-01-24 Thread Martin Pitt
Hi PostgreSQL developers! Debian's security audit team recently reviewed PostgreSQL for insecure temporary file usage and found that a lot of the developer tools and also some build tools are vulnerable against symlink attacks. Please see http://bugs.debian.org/291962 for the detailled repor