Bug#671255: CVE-2012-2451: CWE-377 Insecure Temporary File

gregor herrmann gregoa at debian.org
Sun May 6 21:05:26 UTC 2012


On Sun, 06 May 2012 22:48:45 +0200, Cyril Brulebois wrote:

> (strange to see your mail target the bug report and no-one else; Cc
> added manually.)

(Thanks for adding the CCs, and sorry for the confusion; I bounced
the mail later after missing the CCs in my first try.)
 
> > Dear security and release teams: Please advise on how to proceed;
> > does s-p-u sound right for this isse?
> I'm happy to take it for s-p-u, but the merge window is supposed to
> close this weekend. Given the fix looks pretty straightforward, I think
> I'd take it even if that's a little late. Adam, do you concur?

Thank you. Let's see what Adam says afte reviewing the diff.
 

Cheers,
gregor

-- 
 .''`.  Homepage: http://info.comodo.priv.at/ - OpenPGP key 0xBB3A68018649AA06
 : :' : Debian GNU/Linux user, admin, and developer  -  http://www.debian.org/
 `. `'  Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe
   `-   NP: Little Walter: Mean Old World
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-perl-maintainers/attachments/20120506/4b7a05dc/attachment-0001.pgp>


More information about the pkg-perl-maintainers mailing list