Bug#810924: Reassign to perl

Niko Tyni ntyni at debian.org
Sat Jan 30 08:25:09 UTC 2016


found 810924 5.22.1-4
forwarded 810924 https://rt.perl.org/Ticket/Display.html?id=127322
tag 810924 patch fixed-upstream pending
thanks

On Thu, Jan 21, 2016 at 05:18:41PM +0000, Mark Hindley wrote:
 
> In perl 5.22.1 IO::File->new_tmpfile returns a file with mode 0000. Trying to
> reopen this within the same process then fails with permission denied. In perl
> versions prior to this the temporary file has mode 0600.

Thanks. I forwarded this upstream in
 https://rt.perl.org/Ticket/Display.html?id=127322
but it took them a while to assess potential security implications.
In the end those were deemed minor enough that the fix was released
without the full security coordination process.

I'm attaching the patch that was applied upstream. This will be in the
next Debian upload.
-- 
Niko Tyni   ntyni at debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: mkstemp-umask.diff
Type: text/x-diff
Size: 2040 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/perl-maintainers/attachments/20160130/8e34021f/attachment.diff>


More information about the Perl-maintainers mailing list