Subject: CVS commit: pkgsrc/graphics/tuxpaint
From: Adrian Portelli
Date: 2006-01-17 23:48:57
Message id: 20060117224857.89C302DA27@cvs.netbsd.org

Log Message:
Add a patch via Debain to address:
	http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3340

"The vulnerability is caused due to temporary files being created insecurely
in the "/tmp" directory by the tuxpaint-import.sh script. This can be \ 
exploited
via symlink attacks to create or overwrite arbitrary files with the privileges
of the user running the affected script."

Bump to nb6.

Files:
RevisionActionfile
1.35modifypkgsrc/graphics/tuxpaint/Makefile
1.18modifypkgsrc/graphics/tuxpaint/distinfo
1.1addpkgsrc/graphics/tuxpaint/patches/patch-ac