-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 28 Jan 2009 21:54:03 +0000 Source: geordi Binary: geordi Architecture: source amd64 Version: 0:20080725T0146-1+lenny1 Distribution: testing-proposed-updates Urgency: low Maintainer: Chris Lamb <lamby@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: geordi - IRC bot and interactive shell that evaluates C++ snippets Changes: geordi (0:20080725T0146-1+lenny1) testing-proposed-updates; urgency=low . * Ignore (rather than allow) fcntl system call to prevent a DoS. Upstream writes: . By using fcntl with F_SETOWN to make the geordi process the owner of its stdout and then using fcntl again to set O_ASYNC on stdout, the C++ program could have the geordi process receive SIGIO, causing it to shut down. . We only allowed fcntl because g++ appeared to need it. Upon closer inspection, it turns out g++ only uses it to check some flags on the precompiled header fd, and the system call can just be ignored altogether. . Patch backported from upstream darcs repository. Checksums-Sha1: 78db2b08268734c06033ddbdc167ec4f483c35c8 1075 geordi_20080725T0146-1+lenny1.dsc bbd68c2be55e918eb1cdb2935bee49bd9103c5bb 72565 geordi_20080725T0146-1+lenny1.tar.gz f61a873b0e47e5587478f68535853cef17d80d93 828164 geordi_20080725T0146-1+lenny1_amd64.deb Checksums-Sha256: e070ac0c358d19da335fed7baaa1ffb4c69c6a3b9905016253c5f83a18f84acd 1075 geordi_20080725T0146-1+lenny1.dsc 8c789e7a2629bf9c50dfd813f0e064d9edc7b5d94bf9005beb44626b94de31c0 72565 geordi_20080725T0146-1+lenny1.tar.gz 824921df58993d7a17e2462a9f70fd0846803c643e80a8412045645d385ce9ce 828164 geordi_20080725T0146-1+lenny1_amd64.deb Files: 88779e2c27d1afe4fcab613d53c8a830 1075 net optional geordi_20080725T0146-1+lenny1.dsc e5b00c3791bcf0e3bb04d69057a94280 72565 net optional geordi_20080725T0146-1+lenny1.tar.gz 08b03864d2332f86a28ad93b0406ff1b 828164 net optional geordi_20080725T0146-1+lenny1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkmI6NYACgkQ5/8uW2NPmiAuRACfbEVQw0CD5TlVw59FJiBzcnPs /cIAnj3lxvn4bWOb9PgNJl9H+yvAFUab =TV7K -----END PGP SIGNATURE----- Accepted: geordi_20080725T0146-1+lenny1.dsc to pool/main/g/geordi/geordi_20080725T0146-1+lenny1.dsc geordi_20080725T0146-1+lenny1.tar.gz to pool/main/g/geordi/geordi_20080725T0146-1+lenny1.tar.gz geordi_20080725T0146-1+lenny1_amd64.deb to pool/main/g/geordi/geordi_20080725T0146-1+lenny1_amd64.deb