Bug#683584: security update ready for squeeze (3.1.8)

2013-01-19 Thread Salvatore Bonaccorso
Hi Yves, On Mon, Jan 07, 2013 at 09:32:48PM +0100, Yves-Alexis Perez wrote: On lun., 2013-01-07 at 09:11 +0100, Daniel Pocock wrote: On 07/01/13 07:27, Yves-Alexis Perez wrote: On lun., 2013-01-07 at 00:35 +0100, Daniel Pocock wrote: Yes, the 3.1.8 security fix from upstream has

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-19 Thread Daniel Pocock
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 19/01/13 10:09, Salvatore Bonaccorso wrote: Hi Yves, On Mon, Jan 07, 2013 at 09:32:48PM +0100, Yves-Alexis Perez wrote: On lun., 2013-01-07 at 09:11 +0100, Daniel Pocock wrote: On 07/01/13 07:27, Yves-Alexis Perez wrote: On lun.,

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-19 Thread Salvatore Bonaccorso
Hi Daniel Thanks for you followup! Even better if you (or someone else of pkg-monitoring team) can do the security upload: On Sat, Jan 19, 2013 at 11:22:47AM +0100, Daniel Pocock wrote: Just following up on this - - I've added pkg-monitoring-maintain...@lists.alioth.debian.org to the CC, as

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-19 Thread Yves-Alexis Perez
On sam., 2013-01-19 at 10:09 +0100, Salvatore Bonaccorso wrote: By passing g= argument, it is possible to traverse the path and load another file and execute code from it. Attached is the debdiff against 3.1.7-1 in squeeze. Part of the diff (the is_numeric() parts mainly) seems missing. Is

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-19 Thread Salvatore Bonaccorso
Hi On Sat, Jan 19, 2013 at 08:36:08PM +0100, Yves-Alexis Perez wrote: On sam., 2013-01-19 at 10:09 +0100, Salvatore Bonaccorso wrote: By passing g= argument, it is possible to traverse the path and load another file and execute code from it. Attached is the debdiff against 3.1.7-1 in

Bug#683584: [Pkg-monitoring-maintainers] Bug#683584: security update ready for squeeze (3.1.8)

2013-01-19 Thread Daniel Pocock
On 19/01/13 21:01, Salvatore Bonaccorso wrote: Hi On Sat, Jan 19, 2013 at 08:36:08PM +0100, Yves-Alexis Perez wrote: On sam., 2013-01-19 at 10:09 +0100, Salvatore Bonaccorso wrote: By passing g= argument, it is possible to traverse the path and load another file and execute code from it.

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-07 Thread Daniel Pocock
On 07/01/13 07:27, Yves-Alexis Perez wrote: On lun., 2013-01-07 at 00:35 +0100, Daniel Pocock wrote: Yes, the 3.1.8 security fix from upstream has been packaged and has been waiting for security team to process through to the archive Can you elaborate on that?

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-07 Thread Yves-Alexis Perez
On lun., 2013-01-07 at 09:11 +0100, Daniel Pocock wrote: On 07/01/13 07:27, Yves-Alexis Perez wrote: On lun., 2013-01-07 at 00:35 +0100, Daniel Pocock wrote: Yes, the 3.1.8 security fix from upstream has been packaged and has been waiting for security team to process through to the

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-06 Thread Daniel Pocock
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 05/01/13 16:21, Salvatore Bonaccorso wrote: Hi Daniel On Wed, Aug 15, 2012 at 05:49:00PM +, Daniel Pocock wrote: Upstream have released 3.1.8 which only differs from 3.1.7 by adding the fix for the security issue It has now been

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-06 Thread Yves-Alexis Perez
On lun., 2013-01-07 at 00:35 +0100, Daniel Pocock wrote: Yes, the 3.1.8 security fix from upstream has been packaged and has been waiting for security team to process through to the archive Can you elaborate on that? -- Yves-Alexis signature.asc Description: This is a digitally signed

Bug#683584: security update ready for squeeze (3.1.8)

2013-01-05 Thread Salvatore Bonaccorso
Hi Daniel On Wed, Aug 15, 2012 at 05:49:00PM +, Daniel Pocock wrote: Upstream have released 3.1.8 which only differs from 3.1.7 by adding the fix for the security issue It has now been pushed to the git.debian.org VCS for building the Ganglia package It is on the squeeze branch and

Bug#683584: security update ready for squeeze (3.1.8)

2012-08-15 Thread Daniel Pocock
Upstream have released 3.1.8 which only differs from 3.1.7 by adding the fix for the security issue It has now been pushed to the git.debian.org VCS for building the Ganglia package It is on the squeeze branch and ready for someone to build and upload a binary package Regards, Daniel --