[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2009-07-18 Thread Hew McLachlan
** Changed in: gallery2 (Ubuntu Dapper)
   Status: New => Won't Fix

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2009-07-18 Thread Launchpad Bug Tracker
** Branch linked: lp:~ubuntu-branches/ubuntu/edgy/smarty/edgy-security

** Branch linked: lp:ubuntu/dapper-updates/smarty

** Branch linked: lp:~ubuntu-branches/ubuntu/feisty/smarty/feisty-
security

** Branch linked: lp:~ubuntu-branches/ubuntu/gutsy/smarty/gutsy-security

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2009-07-18 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/karmic/smarty

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2009-05-07 Thread Sergio Zanchetta
The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

** Changed in: gallery2 (Ubuntu Gutsy)
   Status: New => Won't Fix

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-12-14 Thread Hew McLachlan
Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued
for this release. Marking Feisty as Won't Fix.

** Changed in: gallery2 (Ubuntu Feisty)
   Status: New => Won't Fix

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-09-09 Thread Launchpad Bug Tracker
This bug was fixed in the package gallery2 - 2.2.4-1ubuntu0.1

---
gallery2 (2.2.4-1ubuntu0.1) hardy-security; urgency=low

  * SECURITY UPDATE: multiple cross-site scripting, information disclosure,
and restriction bypass vulnerabilities (LP: #242671), and arbitrary code
execution (LP: #202422)
- lib/smarty/plugins/modifier.regex_replace.php: Don't look past a NULL in
  the search string. Fixes possible arbitrary code execution. Patch from
  smarty upstream.
- modules/core/ItemAdd.inc: Flatten the contents of ZIP archives if they
  are being uploaded by a user without subalbum privileges. Patch from
  upstream svn.
- modules/core/classes/GalleryUrlGenerator.class,
  modules/rewrite/classes/parsers/modrewrite/ModRewriteUrlGenerator:
  Properly remove illegal characters from URLs. Patch from upstream svn.
- modules/core/classes/Gallery{Embed,PhpVm}.class: More thoroughly verify
  that the remote address isn't being spoofed. Patch from upstream svn.
- modules/password/PasswordOption.inc: Only allow password protection of
  items already password protected or albums, as single items cannot
  reliably be password protected. Patch from upstream svn.
- modules/albumselect/Callbacks.inc: Add session permissions to keys for
  the album list cache, to avoid hidden album disclosure. Patch from
  upstream svn.
- */MANIFEST: Drop modified files to please the browser-based installer.
- References:
  + CVE-2008-1066
  + CVE-2008-2720
  + CVE-2008-2721
  + CVE-2008-2722
  + CVE-2008-2723
  + CVE-2008-2724

 -- William Grant <[EMAIL PROTECTED]>   Wed, 25 Jun 2008 13:47:58 +1000

** Changed in: gallery2 (Ubuntu Hardy)
   Status: New => Fix Released

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2720

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2721

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2722

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2723

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2724

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-07-24 Thread Hew McLachlan
Ubuntu Edgy Eft is no longer supported, so a SRU will not be issued for
this release. Marking Edgy as Won't Fix.

** Changed in: gallery2 (Ubuntu Edgy)
   Status: New => Won't Fix

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-07-11 Thread Bug Watch Updater
** Changed in: gallery2 (Debian)
   Status: New => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-06-24 Thread Bug Watch Updater
** Changed in: gallery2 (Debian)
   Status: Unknown => New

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-06-24 Thread William Grant
gallery2 is also affected, as it has a vulnerable embedded copy. It's
fixed in Intrepid.

** Also affects: gallery2 (Ubuntu)
   Importance: Undecided
   Status: New

** Bug watch added: Debian Bug tracker #471160
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=471160

** Also affects: gallery2 (Debian) via
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=471160
   Importance: Unknown
   Status: Unknown

** Changed in: gallery2 (Ubuntu)
   Status: New => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-24 Thread Jamie Strandboge
** Changed in: smarty (Ubuntu Edgy)
   Status: Fix Committed => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-24 Thread Launchpad Bug Tracker
This bug was fixed in the package smarty - 2.6.14-1ubuntu0.7.04.1

---
smarty (2.6.14-1ubuntu0.7.04.1) feisty-security; urgency=low

  * SECURITY UPDATE: (LP: #202422)
   + libs/plugins/modifier.regex_replace.php
- The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
  by Serendipity (S9Y) and other products, allows attackers to call 
arbitrary
  PHP functions via templates, related to a '\0' character in a search 
string.

  * References
   + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
   + http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492

 -- Emanuele Gentili <[EMAIL PROTECTED]>   Sat, 15 Mar 2008
07:21:09 +0100

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-24 Thread Launchpad Bug Tracker
This bug was fixed in the package smarty - 2.6.18-1ubuntu2.1

---
smarty (2.6.18-1ubuntu2.1) gutsy-security; urgency=low

  * SECURITY UPDATE: (LP: #202422)
   + libs/plugins/modifier.regex_replace.php
- The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
  by Serendipity (S9Y) and other products, allows attackers to call 
arbitrary
  PHP functions via templates, related to a '\0' character in a search 
string.

  * References
   + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
   + http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492

 -- Emanuele Gentili <[EMAIL PROTECTED]>   Sat, 15 Mar 2008
07:09:26 +0100

** Changed in: smarty (Ubuntu Gutsy)
   Status: Fix Committed => Fix Released

** Changed in: smarty (Ubuntu Feisty)
   Status: Fix Committed => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-24 Thread Jamie Strandboge
smarty (2.6.11-1ubuntu0.1) dapper-security; urgency=low

  * SECURITY UPDATE: (LP: #202422)
   + libs/plugins/modifier.regex_replace.php
- The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
  by Serendipity (S9Y) and other products, allows attackers to call 
arbitrary
  PHP functions via templates, related to a '\0' character in a search 
string.

  * References
   + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
   + http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492

 -- Emanuele Gentili <[EMAIL PROTECTED]>  Sat, 15 Mar 2008
07:33:32 +0100


** Changed in: smarty (Ubuntu Dapper)
   Status: Fix Committed => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-21 Thread Jamie Strandboge
Thanks Emanuele!

** Changed in: smarty (Ubuntu Dapper)
   Status: In Progress => Fix Committed

** Changed in: smarty (Ubuntu Edgy)
   Status: In Progress => Fix Committed

** Changed in: smarty (Ubuntu Feisty)
   Status: In Progress => Fix Committed

** Changed in: smarty (Ubuntu Gutsy)
   Status: In Progress => Fix Committed

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-21 Thread Emanuele Gentili

** Attachment added: "edgy_smarty_2.6.14-1ubuntu0.6.10.1.debdiff"
   
http://launchpadlibrarian.net/12783896/edgy_smarty_2.6.14-1ubuntu0.6.10.1.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-21 Thread Emanuele Gentili

** Attachment added: "feisty_smarty_2.6.14-1ubuntu0.7.04.1.debdiff"
   
http://launchpadlibrarian.net/12783891/feisty_smarty_2.6.14-1ubuntu0.7.04.1.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-21 Thread Jamie Strandboge
Thanks for supplying the debdiffs for dapper - gutsy, Emanuele.  The
edgy and feisty diffs do not have the proper version number as specified
in https://wiki.ubuntu.com/SecurityUpdateProcedures. Can you update that
and resubmit?  Thanks again!

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-19 Thread Launchpad Bug Tracker
This bug was fixed in the package smarty - 2.6.18-1ubuntu3

---
smarty (2.6.18-1ubuntu3) hardy; urgency=low

  * SECURITY UPDATE: (LP: #202422)
   + libs/plugins/modifier.regex_replace.php
- The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
  by Serendipity (S9Y) and other products, allows attackers to call 
arbitrary
  PHP functions via templates, related to a '\0' character in a search 
string.

  * References
   + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
   + http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492

 -- Emanuele Gentili <[EMAIL PROTECTED]>   Sat, 15 Mar 2008
06:54:31 +0100

** Changed in: smarty (Ubuntu Hardy)
   Status: Fix Committed => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-19 Thread Luca Falavigna
Uploaded, thanks ;)

** Changed in: smarty (Ubuntu Hardy)
   Status: In Progress => Fix Committed

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-16 Thread Emanuele Gentili
** Changed in: smarty (Ubuntu Gutsy)
   Importance: Undecided => Medium
 Assignee: (unassigned) => Emanuele Gentili (emgent)
   Status: New => In Progress

** Changed in: smarty (Ubuntu Feisty)
   Importance: Undecided => Medium
 Assignee: (unassigned) => Emanuele Gentili (emgent)
   Status: New => In Progress

** Changed in: smarty (Ubuntu Edgy)
   Importance: Undecided => Medium
 Assignee: (unassigned) => Emanuele Gentili (emgent)
   Status: New => In Progress

** Changed in: smarty (Ubuntu Dapper)
   Importance: Undecided => Medium
 Assignee: (unassigned) => Emanuele Gentili (emgent)
   Status: New => In Progress

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-16 Thread Bug Watch Updater
** Changed in: smarty (Debian)
   Status: New => Fix Released

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-15 Thread Bug Watch Updater
** Changed in: smarty (Debian)
   Status: Unknown => New

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-15 Thread Emanuele Gentili
** Changed in: smarty (Ubuntu)
   Status: Confirmed => In Progress

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-14 Thread Emanuele Gentili

** Attachment added: "dapper_smarty_2.6.11-1ubuntu0.1.debdiff"
   
http://launchpadlibrarian.net/12683095/dapper_smarty_2.6.11-1ubuntu0.1.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-14 Thread Emanuele Gentili

** Attachment added: "edgy_smarty_2.6.14-1ubuntu0.6.10.debdiff"
   
http://launchpadlibrarian.net/12683082/edgy_smarty_2.6.14-1ubuntu0.6.10.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-14 Thread Emanuele Gentili

** Attachment added: "feisty_smarty_2.6.14-1ubuntu0.7.04.debdiff"
   
http://launchpadlibrarian.net/12683072/feisty_smarty_2.6.14-1ubuntu0.7.04.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-14 Thread Emanuele Gentili

** Attachment added: "gutsy_smarty_2.6.18-1ubuntu2.1.debdiff"
   http://launchpadlibrarian.net/12683052/gutsy_smarty_2.6.18-1ubuntu2.1.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 202422] Re: CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via templates

2008-03-14 Thread Emanuele Gentili

** Attachment added: "hardy_smarty_2.6.18-1ubuntu3.debdiff"
   http://launchpadlibrarian.net/12683015/hardy_smarty_2.6.18-1ubuntu3.debdiff

-- 
CVE-2008-1066 smarty allows attackers to call arbitrary PHP functions via 
templates
https://bugs.launchpad.net/bugs/202422
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs