develooper Front page | perl.perl5.porters | Postings from February 2004

Re: [perl #15063] /tmp issues

Thread Previous | Thread Next
From:
Nicholas Clark
Date:
February 28, 2004 09:07
Subject:
Re: [perl #15063] /tmp issues
Message ID:
20040228170651.GS46380@plum.flirble.org
On Sun, Feb 01, 2004 at 03:41:34PM +0000, Dave Mitchell wrote:
> On Mon, Jan 26, 2004 at 01:22:18AM +0300, Solar Designer wrote:
> > Hi,
> > 
> > Well, our package has been updated to Perl 5.8.3, and attached to this
> > message you can find the new temporary file handling patch.
> 
> Thanks, applied to bleedperl as change #22255, except for the following:

Change 22258 by davem@davem-percy on 2004/02/01 17:40:02

        Subject: Re: [perl #15063] /tmp issues
        From: Solar Designer <solar@openwall.com> 
        Date: Mon, 26 Jan 2004 01:22:18 +0300
        Message-ID: <20040125222218.GA13499@openwall.com>

        Remove insecure usage of /tmp from code and documentation

Affected files ...

... //depot/perl/ext/DB_File/DB_File.pm#48 edit
... //depot/perl/ext/DB_File/t/db-recno.t#27 edit
... //depot/perl/ext/Devel/PPPort/PPPort.pm#30 edit
... //depot/perl/ext/IO/t/io_unix.t#2 edit
... //depot/perl/ext/ODBM_File/ODBM_File.xs#24 edit
... //depot/perl/ext/POSIX/POSIX.pod#38 edit
... //depot/perl/ext/Socket/Socket.pm#27 edit
... //depot/perl/ext/Storable/Storable.pm#48 edit
... //depot/perl/ext/Time/HiRes/Makefile.PL#23 edit
... //depot/perl/lib/CGI/Cookie.pm#16 edit
... //depot/perl/lib/ExtUtils/MakeMaker.pm#117 edit
... //depot/perl/lib/ExtUtils/instmodsh#4 edit
... //depot/perl/lib/Memoize/t/tie.t#8 edit
... //depot/perl/lib/Memoize/t/tie_gdbm.t#5 edit
... //depot/perl/lib/Memoize/t/tie_ndbm.t#8 edit
... //depot/perl/lib/Memoize/t/tie_sdbm.t#11 edit
... //depot/perl/lib/Memoize/t/tie_storable.t#6 edit
... //depot/perl/lib/Shell.pm#18 edit
... //depot/perl/lib/dotsh.pl#9 edit
... //depot/perl/lib/perl5db.pl#104 edit
... //depot/perl/mpeix/nm#4 edit
... //depot/perl/mpeix/relink#7 edit
... //depot/perl/perly.fixer#14 edit
... //depot/perl/pod/perl571delta.pod#18 edit
... //depot/perl/pod/perl58delta.pod#10 edit
... //depot/perl/pod/perldbmfilter.pod#7 edit
... //depot/perl/pod/perldebug.pod#52 edit
... //depot/perl/pod/perlfaq5.pod#56 edit
... //depot/perl/pod/perlfaq8.pod#41 edit
... //depot/perl/pod/perlfunc.pod#426 edit
... //depot/perl/pod/perlipc.pod#53 edit
... //depot/perl/pod/perllexwarn.pod#25 edit
... //depot/perl/pod/perlobj.pod#27 edit
... //depot/perl/pod/perlop.pod#117 edit
... //depot/perl/pod/perlopentut.pod#20 edit
... //depot/perl/utils/c2ph.PL#12 edit


This touches quite a few dual life modules maintained outside the core, yet
it doesn't seem to tweak any version numbers. I presume that this changes
are not yet passed on upstream?

[I was about to merge it to maint then had second thoughts because of this]

Nicholas Clark

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About