Bug#508628: etch-backports still vulnerable

2009-01-19 Thread Holger Levsen
Hi Vincent, On Freitag, 16. Januar 2009, Vincent Bernat wrote: In current version in bpo, there is a patch that allows to use older version of php-mail-mimedecode. It should be better to use it. This is: fix-too-old-php-mail-mime.patch Ah, thanks. That does the trick! :) I'm writing an

Bug#508628: etch-backports still vulnerable

2009-01-19 Thread Holger Levsen
On Montag, 19. Januar 2009, Holger Levsen wrote: I'm writing an announcement for bpo announce now and will then upload 0.1.1-10~bpo to bpo. done signature.asc Description: This is a digitally signed message part.

Bug#508628: etch-backports still vulnerable

2009-01-16 Thread Florian Weimer
* Holger Levsen: install --nodeps -P ~/Software/roundcube/php-mail-mimedecode-1.5.0/debian/php-mail-mimedecode/ -/package.xml Console_Getopt: unrecognized option -- / If I understand this correctly, it seems the syntax used is only

Bug#508628: etch-backports still vulnerable

2009-01-16 Thread Holger Levsen
Hi, On Freitag, 16. Januar 2009, Florian Weimer wrote: -/package.xml looks rather like an unset make variable in debian/rules to me. You're right, thanks for the hint. I then built the package in lenny and saw the problem. debian/rules includes /usr/share/cdbs/1/class/pear.mk which contains

Bug#508628: etch-backports still vulnerable

2009-01-16 Thread Vincent Bernat
OoO En ce début d'après-midi ensoleillé du jeudi 15 janvier 2009, vers 15:34, Holger Levsen hol...@layer-acht.org disait : roundcube needs newer php-mail-mime, so I backported that. That needs newer php-mail-mimedecode, which needs newer dh-make-php to build, so I backported that too. In

Bug#508628: etch-backports still vulnerable

2009-01-15 Thread Holger Levsen
Hi, On Dienstag, 13. Januar 2009, Kingsley Masters wrote: I'd like to comfirm this bug still exists on etch-backports and is being actively exploited. Our Debian server running roundcube was comprimised yesterday though this bug. Kingsley, out of curiosity, do you have suhosin installed? to

Bug#508628: etch-backports still vulnerable

2009-01-15 Thread Kalev Kadak
Holger Levsen wrote: Hi, On Dienstag, 13. Januar 2009, Kingsley Masters wrote: I'd like to comfirm this bug still exists on etch-backports and is being actively exploited. Our Debian server running roundcube was comprimised yesterday though this bug. Kingsley, out of curiosity, do

Bug#508628: etch-backports still vulnerable

2009-01-15 Thread Holger Levsen
Hi, On Donnerstag, 15. Januar 2009, Kalev Kadak wrote: to the roundcube maintainers: do you plan an upload to bpo? I have a backport ready (well, needs testing, but I'm about to do this) which I could upload... I was too fast: roundcube needs newer php-mail-mime, so I backported that.

Bug#508628: etch-backports still vulnerable

2009-01-13 Thread Kingsley Masters
I'd like to comfirm this bug still exists on etch-backports and is being actively exploited. Our Debian server running roundcube was comprimised yesterday though this bug. RMCA Limited registered in England and Wales No.

Bug#508628: etch-backports still vulnerable

2008-12-28 Thread Marco Solieri
Roundcube version in etch-backports is still to version 0.1-4~bpo40+1: it is still unpatched and vulnerable. Bug has been reopened. -- Marco Solieri aka SoujaK signature.asc Description: This is a digitally signed message part.