Bug#373685: CVE-2006-1513: Multiple buffer overflows in abc2ps before 1.3.3 allow for execute arbitrary code

2006-06-19 Thread Anselm Lingnau
Micah Anderson wrote: The patches applied for the sarge security update (DSA 1041-1) need to be applied to the sid version of this package No. The package needs to be removed from the distribution altogether (as far as I'm concerned) -- it hasn't been maintained upstream for ages, and in any

Bug#373685: CVE-2006-1513: Multiple buffer overflows in abc2ps before 1.3.3 allow for execute arbitrary code

2006-06-19 Thread Micah Anderson
Anselm Lingnau wrote: Micah Anderson wrote: The patches applied for the sarge security update (DSA 1041-1) need to be applied to the sid version of this package No. The package needs to be removed from the distribution altogether (as far as I'm concerned) -- it hasn't been maintained

Bug#373685: CVE-2006-1513: Multiple buffer overflows in abc2ps before 1.3.3 allow for execute arbitrary code

2006-06-19 Thread Anselm Lingnau
Micah Anderson wrote: I'm not sure what gives you the idea that I might want to adopt the package, I just filed a security bug against it. Sometimes bugs (of whatever type) are filed by people who actually *use* the package in question and are interested in it as part of Debian. Since I'm

Bug#373685: CVE-2006-1513: Multiple buffer overflows in abc2ps before 1.3.3 allow for execute arbitrary code

2006-06-19 Thread Micah Anderson
Anselm Lingnau wrote: Micah Anderson wrote: I'm not sure what gives you the idea that I might want to adopt the package, I just filed a security bug against it. Sometimes bugs (of whatever type) are filed by people who actually *use* the package in question and are interested in it as

Bug#373685: CVE-2006-1513: Multiple buffer overflows in abc2ps before 1.3.3 allow for execute arbitrary code

2006-06-14 Thread Micah Anderson
Package: abc2ps Severity: important Hi CVE-2006-1513 reads: Multiple buffer overflows in abc2ps allow user-complicit attackers to execute arbitrary code via crafted ABC music files. The patches applied for the sarge security update (DSA 1041-1) need to be applied to the sid version of this