Bug#612034: vulnerability: rewrite arbitrary user file

2011-08-03 Thread Jonathan Wiltshire
Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: lenny (5.0.9) squeeze (6.0.3)

Bug#612034: vulnerability: rewrite arbitrary user file

2011-03-29 Thread Daniel Burrows
The immediate problem should be fixed with 4a021fb5d4963d4e0756fcc182223b05939062d6. Unfortunately, I'm not sure that I can cut a security release before the weekend (it'll take some time and I'm still decobwebbing my dev box). Anyone who wants to cut a security NMU that cherry-picks the

Bug#612034: vulnerability: rewrite arbitrary user file

2011-03-29 Thread Daniel Burrows
On Fri, Feb 04, 2011 at 04:53:54PM -0800, Kees Cook k...@debian.org was heard to say: Package: aptitude Version: 0.6.3-3.2ubuntu1 Severity: grave Tags: security Justification: user security hole User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu natty This bug report was also

Bug#612034: vulnerability: rewrite arbitrary user file

2011-02-04 Thread Kees Cook
Package: aptitude Version: 0.6.3-3.2ubuntu1 Severity: grave Tags: security Justification: user security hole User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu natty This bug report was also filed in Ubuntu and can be found at http://launchpad.net/bugs/607264 The description, from