Bug#827352: jessie-pu: package automake-1.14/1.14.1-4+deb8u1
Control: tags -1 + confirmed
On Wed, 2016-06-15 at 11:12 +0200, Petter Reinholdtsen wrote:
> On my Debian Jessie machine, I would like to fix a security problem with
> automake-1.14 that show up the debsecan report, see
> <URL: https://security-tracker.debian.org/tracker/source-package/automake-1.14 >.
> The issue never got a CVE (no reply to the request), so I point to the
> source package entry instead of the some times changing TEMP reference.
>
> The issue is fixed in automake-1.15, but not in automake-1.14 that is in
> stable but removed from unstable.
>
> The issue is unsafe use of /tmp/. The patch is similar to the code in
> version 1.15.
>
> OK to upload?
Assuming that the resulting package has been tested on stable, please go
ahead, except:
+automake-1.14 (1:1.14.1-4+deb8u1) unstable; urgency=medium
That distribution is a little wrong. :-p "jessie", please.
Regards,
Adam
Reply to: