[Koha-bugs] [Bug 6627] [security] insecure file creation

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Thu Jan 5 13:58:14 CET 2012


http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=6627

Ian Walls <ian.walls at bywatersolutions.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |ian.walls at bywatersolutions.
                   |                            |com
       Patch Status|Signed Off                  |Passed QA

--- Comment #8 from Ian Walls <ian.walls at bywatersolutions.com> 2012-01-05 12:58:14 UTC ---
I would also agree that security is more important than an uncommonly used
"feature".

This patch comments out lines rather than deleting them, and sometimes adds
returns before prints would otherwise be executed.  All in all, this is a safe
way of handling this issue until we get a more robust followup to re-enable (or
reimplement) the lost logging

Passed QA

-- 
Configure bugmail: http://bugs.koha-community.org/bugzilla3/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA Contact for the bug.
You are watching all bug changes.


More information about the Koha-bugs mailing list