Bug#315671: webcalendar unauthorized access

2005-07-19 Thread Martin Schulze
Stephen Gran wrote: > Hello all, > > There is a security bug in webcalendar (#315671 and > http://www.securityfocus.com/bid/14072, for reference). Tim is the > maintainer, but does not yet have a debian account, and cannot upload. > We have a fixed version for sarge ready (patch attached). I am

Bug#315671: webcalendar unauthorized access

2005-07-19 Thread Stephen Gran
This one time, at band camp, Martin Schulze said: > While we're at it, have you checked this vulnerability as well? > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0474 My mistake. It appears that this is #295960 and #296280 and was fixed in 0.9.45-3, so it made it to sarge. So the only

Bug#315671: webcalendar unauthorized access

2005-07-19 Thread Stephen Gran
This one time, at band camp, Martin Schulze said: > Stephen Gran wrote: > > Hello all, > > Thanks a lot for contacting us. > > > There is a security bug in webcalendar (#315671 and > > http://www.securityfocus.com/bid/14072, for reference). Tim is the > > maintainer, but does not yet have a debi

Bug#315671: webcalendar unauthorized access

2005-07-18 Thread Martin Schulze
Stephen Gran wrote: > Hello all, Thanks a lot for contacting us. > There is a security bug in webcalendar (#315671 and > http://www.securityfocus.com/bid/14072, for reference). Tim is the > maintainer, but does not yet have a debian account, and cannot upload. > We have a fixed version for sarge

Bug#315671: webcalendar unauthorized access

2005-07-18 Thread Stephen Gran
Hello all, There is a security bug in webcalendar (#315671 and http://www.securityfocus.com/bid/14072, for reference). Tim is the maintainer, but does not yet have a debian account, and cannot upload. We have a fixed version for sarge ready (patch attached). I am happy to upload it for Tim, or y