[Bug 753955] CVE-2011-4114 perl-PAR-Packer: insecure temporary directory handling

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=753955

--- Comment #9 from Petr Pisar <ppisar@xxxxxxxxxx> 2011-12-06 09:23:39 EST ---
How to test:

Create /tmp/par-$(USER) directory with 0777 mode (or owned by different user,
or create an other user's symlink). Create a PAR archive from a perl script (pp
--par SCRIPT).

Test perl-PAR by running `perl -MPAR=./a.par SCRIPT'. Test perl-PAR-Packer by
running `parl ./a.par'.

For unknown reason, you might need perl-PAR-Packer to get running SCRIPT from
./a.par by -MPAR=.

For unknown reason, old parl might not work because of perl version mismatch.
(This becomes fixed after rebuilding old perl-PAR-Packer against current perl.)

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
--
Fedora Extras Perl SIG
http://www.fedoraproject.org/wiki/Extras/SIGs/Perl
perl-devel mailing list
perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/perl-devel



[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite Information]
  Powered by Linux