Subject: | Authen::Captcha is not Taint safe |
Date: | Sat, 17 Nov 2007 10:31:37 -0400 |
To: | bug-Authen-Captcha [...] rt.cpan.org |
From: | Ernesto Hernandez-Novich <emhnemhn [...] gmail.com> |
I'm the current maintainer of the Authen::Captcha package for Debian
GNU/Linux. I've received a bug report [1] regarding Authen::Captcha not
being Taint safe. The bug report has a sample code fragment showing the
bug, along with a working patch.
I've applied the patch, tested it and feel quite comfortable with it. I
think it would be nice if the patch got applied upstream. I will rather
package a new upstream version having the patch, than the alternative of
having to distribute the patch with Debian.
Please let me know if I can be of assistance.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=409731
--
Ernesto Hernández-Novich - Linux 2.6.18 i686 - Unix: Live free or die!
Geek by nature, Linux by choice, Debian of course.
If you can't aptitude it, it isn't useful or doesn't exist.
GPG Key Fingerprint = 438C 49A2 A8C7 E7D7 1500 C507 96D6 A3D6 2F4C 85E3