Re: CVE-2008-5138 pam_mount insecure tempfile creation - to update or not?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Till!

Comment added to BZ as well...

On Fri, 21 Nov 2008 22:51:32 +0100 Till Maas <opensource@xxxxxxxxx>
wrote:

> https://bugzilla.redhat.com/show_bug.cgi?id=472109#c2
> 
> The question is now, whether I should update the package without the
> affected script to make everyone aware of this or just keep it as is.

This has a very low impact due to the reasons you have explained.  For
Red Hat Enterprise Linux we tend to postpone fixing low impact issues,
it should be fine to deal with this once there's a better reason to do
new packages.

-- 
Tomas Hoger / Red Hat Security Response Team

--
Fedora-security-list mailing list
Fedora-security-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-security-list

[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Coolkey]

  Powered by Linux