[tryton-debian] Bug#749073: Bug#749073: python-suds: does not delete directories in /tmp, causing DoS

Mathias Behrle mathiasb at m9s.biz
Mon May 26 11:03:46 UTC 2014


* Ondrej Zary: " [tryton-debian] Bug#749073: python-suds: does not delete
  directories in /tmp, causing DoS" (Fri, 23 May 2014 19:10:31 +0200):

> Package: python-suds
> Version: 0.3.9-1+deb6u1
> Severity: serious
> Justification: breaks unrelated software
> 
> 
> The deb6u1 update to python-suds fixed insecure temporary directory
> creation (/tmp/suds) by creating directories with random names in /tmp.
> 
> However, these directories are never deleted, causing /tmp to reach
> subdirectory limit (~32000 on ext3), breaking various other programs that want
> to create a temporary directory in /tmp (they get "Too many links" error).

Fix for unstable uploaded with suds_0.4.1-14_amd64.changes.


-- 

    Mathias Behrle
    PGP/GnuPG key availabable from any keyserver, ID: 0x8405BBF6
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/tryton-debian/attachments/20140526/943e2300/attachment-0001.sig>


More information about the tryton-debian mailing list