Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-14 Thread Niko Tyni
On Thu, Jan 13, 2011 at 10:35:00PM +, Adam D. Barratt wrote: On Thu, 2011-01-13 at 22:55 +0100, gregor herrmann wrote: I've now uploaded - 3.38-2lenny2 I've flagged the lenny package to be accepted at the next dinstall; While preparing the perl lenny upload I had a look at this. I see

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-14 Thread Adam D. Barratt
On Fri, January 14, 2011 11:40, Niko Tyni wrote: While preparing the perl lenny upload I had a look at this. I see Gregor used my proposed patch from 27 Dec [1]; however I later noticed at least the doc addition in CGI.pm is wrong [2]. Upstream is going to change the documentation back rather

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-14 Thread gregor herrmann
On Fri, 14 Jan 2011 13:40:15 +0200, Niko Tyni wrote: - 3.38-2lenny2 I've flagged the lenny package to be accepted at the next dinstall; While preparing the perl lenny upload I had a look at this. I see Gregor used my proposed patch from 27 Dec [1]; however I later noticed at least the doc

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-14 Thread gregor herrmann
On Fri, 14 Jan 2011 13:08:37 -, Adam D. Barratt wrote: So I'd like permission to upload libcgi-pm-perl 3.38-2lenny3 as seen in the attachments - the first one is the debdiff against 3.38-2lenny2 in proposed-updates, the second one is against 3.38-2lenny1 in stable. Yes, that would be

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-14 Thread Adam D. Barratt
On Fri, 2011-01-14 at 23:29 +0100, gregor herrmann wrote: On Fri, 14 Jan 2011 13:08:37 -, Adam D. Barratt wrote: So I'd like permission to upload libcgi-pm-perl 3.38-2lenny3 as seen in the attachments - the first one is the debdiff against 3.38-2lenny2 in proposed-updates, the

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-13 Thread gregor herrmann
On Tue, 11 Jan 2011 22:16:23 +0200, Niko Tyni wrote: I've also updated libcgi-pm-perl in the pkg-perl SVN repository to 3.51, which fixes this. I didn't upload it yet as my time window for this is closing fast. Thanks! It would be great if somebody could pick up this and the tpu upload of

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-13 Thread Adam D. Barratt
On Thu, 2011-01-13 at 22:55 +0100, gregor herrmann wrote: I've now uploaded - 3.51-1 - 3.49-1squeeze1 - 3.38-2lenny2 to the respective suites. I was a bit hesitant since I haven't seen a comment from the RT about the uploads to lenny/squeeeze; but they can still decide now if they accept

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-13 Thread gregor herrmann
On Thu, 13 Jan 2011 22:35:00 +, Adam D. Barratt wrote: I was a bit hesitant since I haven't seen a comment from the RT about the uploads to lenny/squeeeze; but they can still decide now if they accept the packages or not :) We were so keen for squeeze that Julien and I both added

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-13 Thread Niko Tyni
On Thu, Jan 13, 2011 at 10:35:00PM +, Adam D. Barratt wrote: On Thu, 2011-01-13 at 22:55 +0100, gregor herrmann wrote: I've now uploaded - 3.38-2lenny2 I was a bit hesitant since I haven't seen a comment from the RT about the uploads to lenny/squeeeze; but they can still decide now

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-11 Thread Niko Tyni
On Fri, Jan 07, 2011 at 02:48:28PM +0200, Niko Tyni wrote: Done, just uploaded perl/5.10.1-17 with the attached patch. I've also updated libcgi-pm-perl in the pkg-perl SVN repository to 3.51, which fixes this. I didn't upload it yet as my time window for this is closing fast. It would be great

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-07 Thread Niko Tyni
On Thu, Jan 06, 2011 at 10:37:11PM +0200, Niko Tyni wrote: On Mon, Dec 27, 2010 at 04:23:40PM +0200, Niko Tyni wrote: Assuming this is the case, I'm attaching preliminary patches for 3.29 (perl-modules / lenny) 3.38 (libcgi-pm-perl / lenny) 3.43 (perl-modules / squeeze + sid)

Bug#606995: Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-07 Thread Adam D. Barratt
On Fri, January 7, 2011 12:48, Niko Tyni wrote: Done, just uploaded perl/5.10.1-17 with the attached patch. Changes: perl (5.10.1-17) unstable; urgency=medium . * [SECURITY] CVE-2010-2761 CVE-2010-4410 CVE-2010-4411: fix CGI.pm MIME boundary and multiline header vulnerabilities.

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-07 Thread Moritz Muehlenhoff
On Fri, Jan 07, 2011 at 02:48:28PM +0200, Niko Tyni wrote: On Thu, Jan 06, 2011 at 10:37:11PM +0200, Niko Tyni wrote: On Mon, Dec 27, 2010 at 04:23:40PM +0200, Niko Tyni wrote: Assuming this is the case, I'm attaching preliminary patches for 3.29 (perl-modules / lenny) 3.38

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-06 Thread Niko Tyni
On Mon, Dec 27, 2010 at 04:23:40PM +0200, Niko Tyni wrote: Assuming this is the case, I'm attaching preliminary patches for 3.29 (perl-modules / lenny) 3.38 (libcgi-pm-perl / lenny) 3.43 (perl-modules / squeeze + sid) 3.49 (libcgi-pm-perl / squeeze) 3.50 (libcgi-pm-perl / sid) They

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-05 Thread Niko Tyni
On Mon, Dec 27, 2010 at 04:23:40PM +0200, Niko Tyni wrote: On Mon, Dec 27, 2010 at 03:33:21PM +0200, Niko Tyni wrote: On Wed, Dec 08, 2010 at 08:53:28PM +0100, Moritz Muehlenhoff wrote: On Wed, Dec 08, 2010 at 08:35:47PM +0100, Ansgar Burchardt wrote: Moritz Muehlenhoff j...@debian.org

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-04 Thread gregor herrmann
On Mon, 03 Jan 2011 19:15:03 +0100, Moritz Muehlenhoff wrote: On Mon, Dec 27, 2010 at 04:12:16PM +0100, gregor herrmann wrote: On Mon, 27 Dec 2010 16:23:40 +0200, Niko Tyni wrote: Assuming this is the case, I'm attaching preliminary patches for Thanks! Could you upload the fixes targeted

Bug#606995: Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-04 Thread Julien Cristau
On Tue, Jan 4, 2011 at 19:45:56 +0100, gregor herrmann wrote: On Mon, 03 Jan 2011 19:15:03 +0100, Moritz Muehlenhoff wrote: On Mon, Dec 27, 2010 at 04:12:16PM +0100, gregor herrmann wrote: On Mon, 27 Dec 2010 16:23:40 +0200, Niko Tyni wrote: Assuming this is the case, I'm attaching

Bug#606995: Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2011-01-03 Thread Moritz Muehlenhoff
On Mon, Dec 27, 2010 at 04:12:16PM +0100, gregor herrmann wrote: tag 606370 + patch tag 606995 + patch thanks On Mon, 27 Dec 2010 16:23:40 +0200, Niko Tyni wrote: http://security-tracker.debian.org/tracker/CVE-2010-2761 http://security-tracker.debian.org/tracker/CVE-2010-4410

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-27 Thread Niko Tyni
On Wed, Dec 08, 2010 at 08:53:28PM +0100, Moritz Muehlenhoff wrote: On Wed, Dec 08, 2010 at 08:35:47PM +0100, Ansgar Burchardt wrote: Moritz Muehlenhoff j...@debian.org writes: Three security issues have been reported in libcgi-pm-perl:

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-27 Thread Niko Tyni
On Mon, Dec 27, 2010 at 03:33:21PM +0200, Niko Tyni wrote: On Wed, Dec 08, 2010 at 08:53:28PM +0100, Moritz Muehlenhoff wrote: On Wed, Dec 08, 2010 at 08:35:47PM +0100, Ansgar Burchardt wrote: Moritz Muehlenhoff j...@debian.org writes: Three security issues have been reported in

Bug#606379: Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-27 Thread gregor herrmann
tag 606370 + patch tag 606995 + patch thanks On Mon, 27 Dec 2010 16:23:40 +0200, Niko Tyni wrote: http://security-tracker.debian.org/tracker/CVE-2010-2761 http://security-tracker.debian.org/tracker/CVE-2010-4410 http://security-tracker.debian.org/tracker/CVE-2010-4411 I'm not

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-09 Thread Niko Tyni
On Wed, Dec 08, 2010 at 07:47:18PM +0100, Moritz Muehlenhoff wrote: Package: libcgi-pm-perl Version: 3.49-1 Severity: grave Tags: security Three security issues have been reported in libcgi-pm-perl: http://security-tracker.debian.org/tracker/CVE-2010-2761

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-08 Thread Moritz Muehlenhoff
Package: libcgi-pm-perl Version: 3.49-1 Severity: grave Tags: security Three security issues have been reported in libcgi-pm-perl: http://security-tracker.debian.org/tracker/CVE-2010-2761 http://security-tracker.debian.org/tracker/CVE-2010-4410

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-08 Thread gregor herrmann
clone 606370 -1 reassign -1 libcgi-simple-perl thanks On Wed, 08 Dec 2010 19:47:18 +0100, Moritz Muehlenhoff wrote: Three security issues have been reported in libcgi-pm-perl: http://security-tracker.debian.org/tracker/CVE-2010-2761 http://security-tracker.debian.org/tracker/CVE-2010-4410

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-08 Thread Ansgar Burchardt
clone 606370 -1 found 606370 3.38-2lenny1 reassign -1 libcgi-simple-perl 1.105-1 thanks Moritz Muehlenhoff j...@debian.org writes: Three security issues have been reported in libcgi-pm-perl: http://security-tracker.debian.org/tracker/CVE-2010-2761

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-08 Thread Moritz Muehlenhoff
On Wed, Dec 08, 2010 at 08:23:56PM +0100, gregor herrmann wrote: clone 606370 -1 reassign -1 libcgi-simple-perl thanks On Wed, 08 Dec 2010 19:47:18 +0100, Moritz Muehlenhoff wrote: Three security issues have been reported in libcgi-pm-perl:

Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

2010-12-08 Thread Moritz Muehlenhoff
On Wed, Dec 08, 2010 at 08:35:47PM +0100, Ansgar Burchardt wrote: clone 606370 -1 found 606370 3.38-2lenny1 reassign -1 libcgi-simple-perl 1.105-1 thanks Moritz Muehlenhoff j...@debian.org writes: Three security issues have been reported in libcgi-pm-perl: