Accepted geordi 0:20080725T0146-1+lenny1 (source amd64)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Wed, 28 Jan 2009 21:54:03 +0000
Source: geordi
Binary: geordi
Architecture: source amd64
Version: 0:20080725T0146-1+lenny1
Distribution: testing-proposed-updates
Urgency: low
Maintainer: Chris Lamb <lamby@debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Description:
geordi - IRC bot and interactive shell that evaluates C++ snippets
Changes:
geordi (0:20080725T0146-1+lenny1) testing-proposed-updates; urgency=low
.
* Ignore (rather than allow) fcntl system call to prevent a DoS. Upstream
writes:
.
By using fcntl with F_SETOWN to make the geordi process the owner of its
stdout and then using fcntl again to set O_ASYNC on stdout, the C++
program could have the geordi process receive SIGIO, causing it to shut
down.
.
We only allowed fcntl because g++ appeared to need it. Upon closer
inspection, it turns out g++ only uses it to check some flags on the
precompiled header fd, and the system call can just be ignored
altogether.
.
Patch backported from upstream darcs repository.
Checksums-Sha1:
78db2b08268734c06033ddbdc167ec4f483c35c8 1075 geordi_20080725T0146-1+lenny1.dsc
bbd68c2be55e918eb1cdb2935bee49bd9103c5bb 72565 geordi_20080725T0146-1+lenny1.tar.gz
f61a873b0e47e5587478f68535853cef17d80d93 828164 geordi_20080725T0146-1+lenny1_amd64.deb
Checksums-Sha256:
e070ac0c358d19da335fed7baaa1ffb4c69c6a3b9905016253c5f83a18f84acd 1075 geordi_20080725T0146-1+lenny1.dsc
8c789e7a2629bf9c50dfd813f0e064d9edc7b5d94bf9005beb44626b94de31c0 72565 geordi_20080725T0146-1+lenny1.tar.gz
824921df58993d7a17e2462a9f70fd0846803c643e80a8412045645d385ce9ce 828164 geordi_20080725T0146-1+lenny1_amd64.deb
Files:
88779e2c27d1afe4fcab613d53c8a830 1075 net optional geordi_20080725T0146-1+lenny1.dsc
e5b00c3791bcf0e3bb04d69057a94280 72565 net optional geordi_20080725T0146-1+lenny1.tar.gz
08b03864d2332f86a28ad93b0406ff1b 828164 net optional geordi_20080725T0146-1+lenny1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkmI6NYACgkQ5/8uW2NPmiAuRACfbEVQw0CD5TlVw59FJiBzcnPs
/cIAnj3lxvn4bWOb9PgNJl9H+yvAFUab
=TV7K
-----END PGP SIGNATURE-----
Accepted:
geordi_20080725T0146-1+lenny1.dsc
to pool/main/g/geordi/geordi_20080725T0146-1+lenny1.dsc
geordi_20080725T0146-1+lenny1.tar.gz
to pool/main/g/geordi/geordi_20080725T0146-1+lenny1.tar.gz
geordi_20080725T0146-1+lenny1_amd64.deb
to pool/main/g/geordi/geordi_20080725T0146-1+lenny1_amd64.deb