Your message dated Mon, 26 Mar 2007 23:22:04 +0200
with message-id <[EMAIL PROTECTED]>
and subject line Bug#416318: kdelibs4c2a: Vulnerable to CVE-2007-1564 - 
exploitable passive ftp connections
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: kdelibs4c2a
Version: 4:3.5.5a.dfsg.1-5
Severity: grave
Tags: security patch
Justification: user security hole


The FTP protocol implementation in Konqueror 3.5.5 allows remote servers
to force the client to connect to other servers, perform a proxied port
scan, or obtain sensitive information by specifying an alternate server
address in a FTP PASV command.

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1564

This issue have ben addressed in the -7 upload.

/Sune


--- End Message ---
--- Begin Message ---
Version: 4:3.5.5a.dfsg.1-7

>
> This issue have ben addressed in the -7 upload.

..and marking it closed..

/Sune
-- 
Man, how can I debug the fan?

First of all you neither have to receive from a firewall, nor must overclock 
the microkernel to insert the Fast DVD minitower.

Attachment: pgpk6K3y17Rr2.pgp
Description: PGP signature


--- End Message ---

Reply via email to