Your message dated Sun, 12 Aug 2007 17:47:15 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#437454: fixed in xfce4-terminal 0.2.6-3
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Package: xfce4-terminal
Version: 0.2.5.6rc1-2
Severity: grave
Tags: security, patch
CVE-2007-3770 says:
The terminal_helper_execute function in terminal/terminal.c in Xfce
Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary
commands via shell metacharacters in a crafted link, as demonstrated using
the "Open Link" functionality.
Upstream link: http://bugzilla.xfce.org/show_bug.cgi?id=3383
The attached patch fixes this: the code changes add shell quoting, using
g_shell_quote(), and the *.desktop.in files are modified to avoid
over-quoting (without this, we'd get "'foo'" instead of 'foo').
--
| Darren Salt | linux or ds at | nr. Ashington, | Toon
| RISC OS, Linux | youmustbejoking,demon,co,uk | Northumberland | Army
| + Use more efficient products. Use less. BE MORE ENERGY EFFICIENT.
Confucius say: He who post large binary, get flamed.
01_CVE-2007-3770.patch
Description: Binary data
--- End Message ---
--- Begin Message ---
Source: xfce4-terminal
Source-Version: 0.2.6-3
We believe that the bug you reported is fixed in the latest version of
xfce4-terminal, which is due to be installed in the Debian FTP archive:
xfce4-terminal_0.2.6-3.diff.gz
to pool/main/x/xfce4-terminal/xfce4-terminal_0.2.6-3.diff.gz
xfce4-terminal_0.2.6-3.dsc
to pool/main/x/xfce4-terminal/xfce4-terminal_0.2.6-3.dsc
xfce4-terminal_0.2.6-3_amd64.deb
to pool/main/x/xfce4-terminal/xfce4-terminal_0.2.6-3_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Yves-Alexis Perez <[EMAIL PROTECTED]> (supplier of updated xfce4-terminal
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 12 Aug 2007 18:00:09 +0100
Source: xfce4-terminal
Binary: xfce4-terminal
Architecture: source amd64
Version: 0.2.6-3
Distribution: unstable
Urgency: high
Maintainer: Debian Xfce Maintainers <[email protected]>
Changed-By: Yves-Alexis Perez <[EMAIL PROTECTED]>
Description:
xfce4-terminal - Xfce terminal emulator
Closes: 437454
Changes:
xfce4-terminal (0.2.6-3) unstable; urgency=high
.
(Yves-Alexis Perez)
* debian/menu: switch to new menu policy.
(Simon Huggins)
* Fix security problem in URL handling code (CVE-2007-3770) thanks to Darren
Salt closes: #437454
* urgency high for the above.
Files:
d8960cd5fd13c5af5debbf92f0bd2af6 941 x11 optional xfce4-terminal_0.2.6-3.dsc
273f5f7976d025dc3f6789894c5a2bbe 14496 x11 optional
xfce4-terminal_0.2.6-3.diff.gz
e4a1af5d70c5540d885e5f2cfebffb91 1266598 x11 optional
xfce4-terminal_0.2.6-3_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGv0OyMQdl+99c4rQRAn+aAJ9eao9E1SozSoc2NA1Sg+VIm3Y8JQCdGyZ0
HNcqrQMEYBoIbG20kQftPWU=
=GZei
-----END PGP SIGNATURE-----
--- End Message ---
_______________________________________________
Pkg-xfce-devel mailing list
[email protected]
http://lists.alioth.debian.org/mailman/listinfo/pkg-xfce-devel