Re: KDE Security Advisory: URI Handler Vulnerabilities

2004-05-18 Thread Chris Cheney
On Mon, May 17, 2004 at 09:01:24PM +0200, Martin Schulze wrote:
> Hi,
> 
> could you tell me which version of kdelibs, kdenetwork (or another
> package if another one is affected) fixes this problem in unstable?
> 
> http://www.kde.org/info/security/advisory-20040517-1.txt
> 
> If you apply the patch, please mention CAN-2004-0411 in the
> changelog file so we can easier track this security problem.

As far as I know it hasn't been fixed yet. I am planning to fix it soon,
the problem is that we already know that kdelibs is going to be broken
again in the next week with the new libcupsys2-gnutls10 upload since no
one every cares to provide oldlibs (gar). I had hoped that the new cups
library would have been allowed into sid this past weekend so I could
have just done one upload instead of hammering the buildds twice with
kdelibs. But from what I have heard AJ stalled it. So I guess I will be
forced to do two uploads. As always I am going to pull current
KDE_3_2_BRANCH for the upload.

Thanks,
Chris


signature.asc
Description: Digital signature


KDE Security Advisory: URI Handler Vulnerabilities

2004-05-17 Thread Martin Schulze
Hi,

could you tell me which version of kdelibs, kdenetwork (or another
package if another one is affected) fixes this problem in unstable?

http://www.kde.org/info/security/advisory-20040517-1.txt

If you apply the patch, please mention CAN-2004-0411 in the
changelog file so we can easier track this security problem.

Regards,

Joey

-- 
Reading is a lost art nowadays.  -- Michael Weber