newsNews: Upload security verification

 
 
Show feedback again
Latest News
Pound version 4.16 posted by gray, Mon Jan 13 07:58:44 2025 - 0 replies
GNU mailutils Version 3.18 posted by gray, Fri Jan 3 16:43:44 2025 - 0 replies
GCIDE version 0.54 posted by gray, Fri Jan 3 16:43:38 2025 - 0 replies
GNU dico version 2.12 posted by gray, Tue Dec 31 10:13:11 2024 - 0 replies
Config::Proxy Version 1.0 posted by gray, Tue Dec 10 13:07:08 2024 - 0 replies
[50 news in archive]

Upload security verification

Item posted by Sergey Poznyakoff <gray> on Sun Jan 3 10:53:20 2010.

In response to the discovery of a potential security problem in Automake versions up to 1.11 (CVE-2009-4029), Puszcza now enforces a security verification procedure on distribution uploads. Any uploaded tarball whose top-level Makefile.in contains this security hole will be rejected. Please, make sure the tarballs you upload are created using Automake v. 1.11.1 (or later).

For more information on CVE-2009-4029, refer to http://thread.gmane.org/gmane.comp.sysutils.autotools.announce/131.

Comments:

No messages in Upload security verification

 

Show feedback again

Back to the top


Powered by Savane 3.1-cleanup+gray