Your message dated Sun, 14 Oct 2007 13:47:42 +0000 with message-id <[EMAIL PROTECTED]> and subject line Bug#444928: fixed in knowledgeroot 0.9.8.4-1.1 has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database)
--- Begin Message ---Package: knowledgeroot Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for knowledgeroot. CVE-2007-5156[0]: | Incomplete blacklist vulnerability in | editor/filemanager/upload/php/upload.php in FCKeditor, as used in | SiteX CMS 0.7.3.beta and probably other products, allows remote | attackers to upload and execute arbitrary PHP code via a file whose | name contains ".php." and has an unknown extension, which is | recognized as a .php file by the Apache HTTP server, a different | vulnerability than CVE-2006-0658 and CVE-2006-2529. If you fix this vulnerability please also include the CVE id in your changelog entry. For further information: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5156 Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.pgprXinHrReOw.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---Source: knowledgeroot Source-Version: 0.9.8.4-1.1 We believe that the bug you reported is fixed in the latest version of knowledgeroot, which is due to be installed in the Debian FTP archive: knowledgeroot_0.9.8.4-1.1.diff.gz to pool/main/k/knowledgeroot/knowledgeroot_0.9.8.4-1.1.diff.gz knowledgeroot_0.9.8.4-1.1.dsc to pool/main/k/knowledgeroot/knowledgeroot_0.9.8.4-1.1.dsc knowledgeroot_0.9.8.4-1.1_all.deb to pool/main/k/knowledgeroot/knowledgeroot_0.9.8.4-1.1_all.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [EMAIL PROTECTED], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Steffen Joeris <[EMAIL PROTECTED]> (supplier of updated knowledgeroot package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [EMAIL PROTECTED]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sun, 14 Oct 2007 13:07:02 +0000 Source: knowledgeroot Binary: knowledgeroot Architecture: source all Version: 0.9.8.4-1.1 Distribution: unstable Urgency: high Maintainer: Frank Habermann <[EMAIL PROTECTED]> Changed-By: Steffen Joeris <[EMAIL PROTECTED]> Description: knowledgeroot - web-based knowledgebase system Closes: 444928 Changes: knowledgeroot (0.9.8.4-1.1) unstable; urgency=high . * Non-maintainer upload by the testing-security team * Changed FCKeditor blacklists to whitelists in order to make sure that remote attackers cannot upload arbitrary PHP code via a file whose name contains unknown extensions (Closes: #444928) Fixes: CVE-2007-5156 Files: b5b2dce118842e01e154a824779576a5 599 web optional knowledgeroot_0.9.8.4-1.1.dsc c0dd552cd01480fe09b2fb35010bcbb4 6574 web optional knowledgeroot_0.9.8.4-1.1.diff.gz 2fd0daaaf7406f11c1a4c663c0687af2 1249104 web optional knowledgeroot_0.9.8.4-1.1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFHEhd162zWxYk/rQcRAiaUAKCdgJkn60nJAb/fdhDUN7Cmn0SYbgCePWAw Ddiy8651p4aem6SbM1ZRZqA= =oC8w -----END PGP SIGNATURE-----
--- End Message ---