[screen-devel] Re: Insecure handling of /tmp/screen-exchange

2009-04-01 Thread Moritz Muehlenhoff
On Wed, Apr 01, 2009 at 02:28:24PM -0700, Adam Lazur wrote: > Moritz Muehlenhoff (j...@inutil.org) said: > > Hi, > > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123 has been assigned > > CVE-2009-1215 and CVE-2009-1214. > > > > Can you tell us under what circumstances /tmp/screen-exchange

[screen-devel] Re: Insecure handling of /tmp/screen-exchange

2009-04-01 Thread Adam Lazur
Moritz Muehlenhoff (j...@inutil.org) said: > Hi, > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123 has been assigned > CVE-2009-1215 and CVE-2009-1214. > > Can you tell us under what circumstances /tmp/screen-exchange is created, > so that the risk/required action can be estimated? write

[screen-devel] Re: Insecure handling of /tmp/screen-exchange

2009-04-01 Thread Jan Christoph Nordholz
Hi Moritz, > Ok, can you or Jan Christop provide updated packages for oldstable-security > and stable-security? I'll come up with a solution. I'm working on it. Regards, Jan signature.asc Description: Digital signature