Bug#287601: vdradmin: Vdradmin.pl script vulnerable to symlink attacks

Javier Fernández-Sanguino Peña pkg-vdr-dvb-devel@lists.alioth.debian.org
Thu, 30 Dec 2004 09:03:54 +0100


--4Ckj6UjgE2iN1+kY
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Dec 29, 2004 at 11:54:08PM +0000, Darren Salt wrote:
> s/in theory// - I'm running vdr 1.3.17 as non-root.
>=20
> > it only needs a small patch to make it possible that vdr can set the
> > system-time. The only problem is that changing this would require a lot=
 of
> > code in the maintainer scripts - patches for this would be very wellcom=
e.
>=20
> Have a look at the .diff.gz for my vdr package :-)

And where can that patch be found? Could you please open up a wishlist bug=
=20
against Debian's 'vdr' package attaching it?

Regards

Javier

--4Ckj6UjgE2iN1+kY
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFB07Zpi4sehJTrj0oRAmxMAJ9tWIzl19ssPfAUsxpziAU3N+270gCgzedc
TGGjv1u1mPMd+eKsR1xNKUM=
=/oV9
-----END PGP SIGNATURE-----

--4Ckj6UjgE2iN1+kY--