-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sun, 23 Jan 2005 23:00:04 +0100 Source: libdbi-perl Binary: libdbi-perl Architecture: source i386 Version: 1.46-6 Distribution: unstable Urgency: high Maintainer: Christian Hammers <ch@debian.org> Changed-By: Christian Hammers <ch@debian.org> Description: libdbi-perl - Perl5 database interface by Tim Bunce Changes: libdbi-perl (1.46-6) unstable; urgency=high . * SECURITY Javier Fernandez-Sanguino Pena from the Debian Security Audit Project discovered that the DBI library, the Perl5 database interface, creates a temporary PID file in an insecure manner. This can be exploited by a malicious user to overwrite arbitrary files owned by the person executing the parts of the library. (DSA 658-1, CAN-2005-0077) Files: b574d9c54111cf8a5fd94df9cfc07471 602 perl optional libdbi-perl_1.46-6.dsc 7d8699eea07f7ffb4adfa548e88549a5 5861 perl optional libdbi-perl_1.46-6.diff.gz 1b7534ca9c6ed7ca9df683b7af201054 606148 perl optional libdbi-perl_1.46-6_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iEYEARECAAYFAkH221wACgkQkR9K5oahGOYzNgCfYCKQ49t1r66xx8C3ixdUQGS1 cSgAnin36Ui9ZvOWNpkJ2DWJoT2WeYXR =JT5B -----END PGP SIGNATURE----- Accepted: libdbi-perl_1.46-6.diff.gz to pool/main/libd/libdbi-perl/libdbi-perl_1.46-6.diff.gz libdbi-perl_1.46-6.dsc to pool/main/libd/libdbi-perl/libdbi-perl_1.46-6.dsc libdbi-perl_1.46-6_i386.deb to pool/main/libd/libdbi-perl/libdbi-perl_1.46-6_i386.deb -- To UNSUBSCRIBE, email to debian-devel-changes-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org