Bug#693076: gatling: Gatling 0.12 has two direcory traversal vulns that were fixed in 0.13

2012-11-12 Thread Jann Horn
Package: gatling Version: 0.12cvs20120114-2 Severity: grave Tags: upstream security Justification: user security hole gatling 0.12 has two directory traversal vulns (one in the handling of Host headers, one in the ftp code) that have been fixed in Gatling 0.13. -- System Information: Debian Rele

Bug#693076: gatling: Gatling 0.12 has two direcory traversal vulns that were fixed in 0.13

2012-11-12 Thread Roland Stigge
Hi! Thanks for reporting! On 12/11/12 20:26, Jann Horn wrote: > Package: gatling > Version: 0.12cvs20120114-2 > Severity: grave > Tags: upstream security > Justification: user security hole > > gatling 0.12 has two directory traversal vulns (one in the handling of Host > headers, one > in the f

Bug#693076: gatling: Gatling 0.12 has two direcory traversal vulns that were fixed in 0.13

2012-11-28 Thread Moritz Muehlenhoff
On Mon, Nov 12, 2012 at 08:40:56PM +0100, Roland Stigge wrote: > Hi! > > Thanks for reporting! > > On 12/11/12 20:26, Jann Horn wrote: > > Package: gatling > > Version: 0.12cvs20120114-2 > > Severity: grave > > Tags: upstream security > > Justification: user security hole > > > > gatling 0.12 ha

Bug#693076: gatling: Gatling 0.12 has two direcory traversal vulns that were fixed in 0.13

2012-11-28 Thread Roland Stigge
On 11/28/2012 05:10 PM, Moritz Muehlenhoff wrote: >>> gatling 0.12 has two directory traversal vulns (one in the handling of Host >>> headers, one >>> in the ftp code) that have been fixed in Gatling 0.13. >> >> Which ones do you mean? (e.g. CVS commits/fixes?) How does it justify >> grave/securit

Bug#693076: gatling: Gatling 0.12 has two direcory traversal vulns that were fixed in 0.13

2012-11-28 Thread Moritz Mühlenhoff
On Wed, Nov 28, 2012 at 05:22:30PM +0100, Roland Stigge wrote: > On 11/28/2012 05:10 PM, Moritz Muehlenhoff wrote: > >>> gatling 0.12 has two directory traversal vulns (one in the handling of > >>> Host headers, one > >>> in the ftp code) that have been fixed in Gatling 0.13. > >> > >> Which ones