From 484fd5d97af2cfb22ed56b7b75d92b4e2994c89c Mon Sep 17 00:00:00 2001 From: Don Armstrong Date: Sun, 21 May 2017 12:41:50 -0700 Subject: [PATCH] document the changes to backport the fix to #862667 --- debian/changelog | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/debian/changelog b/debian/changelog index deeb54a5..7c678eaf 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,11 +1,9 @@ -perltidy (20160302-1) unstable; urgency=medium +perltidy (20140328-2) unstable; urgency=high - * New upstream release - * Die if an existing perltidy.ERR cannot be removed to block overwriting - of arbitrary files by a symlink attack. (closes: #862667) Thanks to - Jakub Wilk for identifying this issue. + * Backport fix for CVE-2016-10374 which fixes insecure file deletion of + perltidy.ERR and perltidy.LOG files (closes: #862667) - -- + -- Don Armstrong Sun, 21 May 2017 12:41:30 -0700 perltidy (20140328-1) unstable; urgency=medium -- 2.39.5