-
Committer:
Bazaar Package Importer
-
Author(s):
Paul Martin
-
Date:
2009-08-06 16:41:26 UTC
-
mto:
(4.3.4 experimental)
-
mto:
This revision was merged to the branch mainline in
revision
12.
-
Revision ID:
james.westby@ubuntu.com-20090806164126-cy3qq858svk2qf0m
* Backport patch from 3.7.8-3 (in experimental):
+ nofollow.patch: If a logfile is a symlink, it may be read when
being compressed, being copied (copy, copytruncate) or mailed.
Secure data (eg. password files) may be exposed. Thanks to
Florian Zumbiehl for getting me thinking about this one.