Bug#329156: closed by Andreas Beckmann <a...@debian.org> (libzvt was removed from Debian)

2015-09-15 Thread paul . szabo
A minute ago I wrote:

> I now see gnome-pty-helper being part of packages
>   libvte9
>   libvte-2.90-9
>   libvte-2.91-0
> and I wonder whether those are just as vulnerable.
> Should I file bug reports against those packages, or would you be able
> to re-assign this but to each of those?

Sorry, now checking things I see that this "clone are reassign" had been
done, and bug#330907
  http://bugs.debian.org/330907
is "alive": all is good, no further action required, 329156 can go.

Thanks, Paul

Paul Szabo   p...@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of SydneyAustralia



Bug#329156: closed by Andreas Beckmann <a...@debian.org> (libzvt was removed from Debian)

2015-09-15 Thread paul . szabo
Dear Andreas,

> #329156: [CAN-2005-0023] /usr/sbin/gnome-pty-helper: writes arbitrary utmp 
> records
> libzvt was removed from Debian in 2008, see #195969 for details on the
> removal.

I now see gnome-pty-helper being part of packages
  libvte9
  libvte-2.90-9
  libvte-2.91-0
and I wonder whether those are just as vulnerable.

Should I file bug reports against those packages, or would you be able
to re-assign this but to each of those?

Thanks, Paul

Paul Szabo   p...@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of SydneyAustralia