GNU bug report logs - #17415
insecure temp file in tramp-uudecode

Previous Next

Package: emacs;

Reported by: Glenn Morris <rgm <at> gnu.org>

Date: Tue, 6 May 2014 04:01:02 UTC

Severity: important

Tags: security

Found in version 24.3.90

Fixed in version 24.4

Done: Michael Albinus <michael.albinus <at> gmx.de>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Michael Albinus <michael.albinus <at> gmx.de>
Cc: tracker <at> debbugs.gnu.org
Subject: bug#17415: closed (insecure temp file in tramp-uudecode)
Date: Tue, 06 May 2014 09:54:02 +0000
[Message part 1 (text/plain, inline)]
Your message dated Tue, 06 May 2014 11:53:03 +0200
with message-id <877g5zgrnk.fsf <at> gmx.de>
and subject line Re: bug#17415: insecure temp file in tramp-uudecode
has caused the debbugs.gnu.org bug report #17415,
regarding insecure temp file in tramp-uudecode
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs <at> gnu.org.)


-- 
17415: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=17415
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Glenn Morris <rgm <at> gnu.org>
To: submit <at> debbugs.gnu.org
Subject: insecure temp file in tramp-uudecode
Date: Tue, 06 May 2014 00:00:06 -0400
Package: emacs
Version: 24.3.90
Severity: important
Tags: security

http://bugs.debian.org/747100 points out that tramp-uudecode (now defined
tramp-sh.el) uses a predictable temp-file name.


[Message part 3 (message/rfc822, inline)]
From: Michael Albinus <michael.albinus <at> gmx.de>
To: Glenn Morris <rgm <at> gnu.org>
Cc: 17415-done <at> debbugs.gnu.org
Subject: Re: bug#17415: insecure temp file in tramp-uudecode
Date: Tue, 06 May 2014 11:53:03 +0200
Version: 24.4

Glenn Morris <rgm <at> gnu.org> writes:

> http://bugs.debian.org/747100 points out that tramp-uudecode (now defined
> tramp-sh.el) uses a predictable temp-file name.

Indeed. I've fixed this in the emacs-24 branch, closing the bug.

Best regards, Michael.


This bug report was last modified 11 years and 112 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.