Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Didier Raboud
found 635549 3.10.6-2 notfound 635549 3.11.10 thanks Hi Moritz, Le mardi, 26 juillet 2011 23.07:01, Moritz Muehlenhoff a écrit : Two security issues have been reported in hplip: 1. Shell command injection in foomatic-rip-hplip: https://bugzilla.novell.com/show_bug.cgi?id=698451 This is

Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Didier Raboud
Le vendredi, 25 novembre 2011 12.16:06, Didier Raboud a écrit : found 635549 3.10.6-2 notfound 635549 3.11.10 thanks Hi Moritz, Le mardi, 26 juillet 2011 23.07:01, Moritz Muehlenhoff a écrit : Two security issues have been reported in hplip: 1. Shell command injection in

Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Didier Raboud
Le vendredi, 25 novembre 2011 12.16:06, Didier Raboud a écrit : 2. Insecure tempfile handling: https://bugzilla.novell.com/show_bug.cgi?id=704608 https://bugs.launchpad.net/hplip/+bug/809904 This is CVE-2011-2722 This seems to be fixed in 3.11.10, hence again, only stable is

Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Didier Raboud
Le vendredi, 25 novembre 2011 12.22:24, Didier Raboud a écrit : Le mardi, 26 juillet 2011 23.07:01, Moritz Muehlenhoff a écrit : 1. Shell command injection in foomatic-rip-hplip: https://bugzilla.novell.com/show_bug.cgi?id=698451 This is CVE-2011-2697 As far as I can see, the

Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Moritz Mühlenhoff
On Fri, Nov 25, 2011 at 12:22:24PM +0100, Didier Raboud wrote: Le vendredi, 25 novembre 2011 12.16:06, Didier Raboud a écrit : found 635549 3.10.6-2 notfound 635549 3.11.10 thanks Hi Moritz, Le mardi, 26 juillet 2011 23.07:01, Moritz Muehlenhoff a écrit : Two security issues

Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Moritz Mühlenhoff
On Fri, Nov 25, 2011 at 02:04:44PM +0100, Didier Raboud wrote: Le vendredi, 25 novembre 2011 12.16:06, Didier Raboud a écrit : 2. Insecure tempfile handling: https://bugzilla.novell.com/show_bug.cgi?id=704608 https://bugs.launchpad.net/hplip/+bug/809904 This is CVE-2011-2722

Bug#635549: [Pkg-hpijs-devel] Bug#635549: #635549: Two hplip security issues

2011-11-25 Thread Mark Purcell
On Sat, 26 Nov 2011 04:38:19 Moritz Mühlenhoff wrote: CVE-2011-2722 itself doesn't warrant a DSA. Could the hplip maintainers please fix this through a point update? http://www.debian.org/doc/manuals/developers-reference/pkgs.html#upload-sta ble Moritz and odyx, Thanks for chasing this down.