From mboxrd@z Thu Jan 1 00:00:00 1970 From: yngves@sources.redhat.com To: yngves@sources.redhat.com Cc: gnats-prs@sourceware.cygnus.com Subject: Re: gnats/52 Date: Sun, 13 May 2001 08:04:00 -0000 Message-id: <20010513150400.7156.qmail@sourceware.cygnus.com> X-SW-Source: 2001-q2/msg00114.html List-Id: The following reply was made to PR gnats/52; it has been noted by GNATS. From: yngves@sources.redhat.com To: gnats-gnats@sourceware.cygnus.com, nobody@sourceware.cygnus.com, phil+gnats@rivendell.apana.org.au, yngves@sources.redhat.com Cc: Subject: Re: gnats/52 Date: 13 May 2001 14:55:42 -0000 Synopsis: send-pr is vulnerable to symlink attacks Responsible-Changed-From-To: unassigned->yngves Responsible-Changed-By: yngves Responsible-Changed-When: Sun May 13 07:55:42 2001 Responsible-Changed-Why: - State-Changed-From-To: open->analyzed State-Changed-By: yngves State-Changed-When: Sun May 13 07:55:42 2001 State-Changed-Why: Fix in hand for Gnats 4. Patch being posted to gnats-devel in a short time. Will use mktemp on systems that support it. Will not change behaviour on platforms that don't have mktemp. http://sources.redhat.com/cgi-bin/gnatsweb.pl?cmd=view&pr=52&database=gnats