diff -Nru libiptables-parse-perl-1.1/debian/changelog libiptables-parse-perl-1.1/debian/changelog --- libiptables-parse-perl-1.1/debian/changelog 2012-03-05 20:36:00.000000000 +0000 +++ libiptables-parse-perl-1.1/debian/changelog 2018-11-02 18:33:01.000000000 +0000 @@ -1,3 +1,17 @@ +libiptables-parse-perl (1.1-1+deb8u1build0.14.04.1) trusty-security; urgency=medium + + * fake sync from Debian + + -- Mike Salvatore Fri, 02 Nov 2018 14:33:01 -0400 + +libiptables-parse-perl (1.1-1+deb8u1) jessie; urgency=medium + + * Team upload. + * Add CVE-2015-8326.patch patch. + CVE-2015-8326: Use of predictable names for temporary files. + + -- Salvatore Bonaccorso Thu, 26 Nov 2015 17:39:36 +0100 + libiptables-parse-perl (1.1-1) unstable; urgency=low * Imported Upstream version 1.1 diff -Nru libiptables-parse-perl-1.1/debian/patches/CVE-2015-8326.patch libiptables-parse-perl-1.1/debian/patches/CVE-2015-8326.patch --- libiptables-parse-perl-1.1/debian/patches/CVE-2015-8326.patch 1970-01-01 00:00:00.000000000 +0000 +++ libiptables-parse-perl-1.1/debian/patches/CVE-2015-8326.patch 2015-11-26 21:30:12.000000000 +0000 @@ -0,0 +1,46 @@ +Description: Don't use predictable names for temporary files + This allows an attacker on a multi-user system to set up symlinks to + overwrite any file the current user has write access to. + . + Don't recommend users of this module to use predictable names either. +Origin: backport, https://github.com/mtrmac/IPTables-Parse/commit/b400b976d81140f6971132e94eb7657b5b0a2b87 +Bug-RedHat: https://bugzilla.redhat.com/show_bug.cgi?id=1267962 +Forwarded: not-needed +Author: Salvatore Bonaccorso +Last-Update: 2015-11-26 +Applied-Upstream: 1.6 + +--- + lib/IPTables/Parse.pm | 7 +++---- + 1 file changed, 3 insertions(+), 4 deletions(-) + +--- a/lib/IPTables/Parse.pm ++++ b/lib/IPTables/Parse.pm +@@ -17,6 +17,7 @@ package IPTables::Parse; + use 5.006; + use POSIX ":sys_wait_h"; + use Carp; ++use File::Temp; + use strict; + use warnings; + use vars qw($VERSION); +@@ -29,8 +30,8 @@ sub new() { + + my $self = { + _iptables => $args{'iptables'} || $args{'ip6tables'} || '/sbin/iptables', +- _iptout => $args{'iptout'} || '/tmp/ipt.out', +- _ipterr => $args{'ipterr'} || '/tmp/ipt.err', ++ _iptout => $args{'iptout'} || mktemp('/tmp/ipt.out.XXXXXX'), ++ _ipterr => $args{'ipterr'} || mktemp('/tmp/ipt.err.XXXXXX'), + _ipt_alarm => $args{'ipt_alarm'} || 30, + _debug => $args{'debug'} || 0, + _verbose => $args{'verbose'} || 0, +@@ -701,8 +702,6 @@ IPTables::Parse - Perl extension for par + + my %opts = ( + 'iptables' => $ipt_bin, +- 'iptout' => '/tmp/iptables.out', +- 'ipterr' => '/tmp/iptables.err', + 'debug' => 0, + 'verbose' => 0 + ); diff -Nru libiptables-parse-perl-1.1/debian/patches/series libiptables-parse-perl-1.1/debian/patches/series --- libiptables-parse-perl-1.1/debian/patches/series 1970-01-01 00:00:00.000000000 +0000 +++ libiptables-parse-perl-1.1/debian/patches/series 2015-11-26 21:30:12.000000000 +0000 @@ -0,0 +1 @@ +CVE-2015-8326.patch