Re: [Pharo-project] [squeak-dev] Security Vunerability in SqueakSource

2011-03-21 Thread Tobias Pape
Am 2011-03-21 um 03:24 schrieb Matthew Fulmer: > As demonstrated by the VMMaker team, SqueakSource has a rather > serious security vunerability: > > http://bugs.squeak.org/view.php?id=7617 > > Below is the dialog that led to this discovery: > Note that SqueakSource 2 and 3 are unaffected of t

Re: [Pharo-project] [squeak-dev] Security Vunerability in SqueakSource

2011-03-21 Thread Marcus Denker
On Mar 21, 2011, at 9:27 AM, Tobias Pape wrote: > Am 2011-03-21 um 03:24 schrieb Matthew Fulmer: > >> As demonstrated by the VMMaker team, SqueakSource has a rather >> serious security vunerability: >> >> http://bugs.squeak.org/view.php?id=7617 >> >> Below is the dialog that led to this discov

Re: [Pharo-project] [squeak-dev] Security Vunerability in SqueakSource

2011-03-21 Thread Bert Freudenberg
It's surprising to me that you find this "news". SqueakSource is simply a WebDAV server. All the versioning logic is local, implemented in Monticello, so allowing overwrites is not really SqueakSource's "fault". Besides, even if SqueakSource disallowed overwriting a version (which it probably

Re: [Pharo-project] [squeak-dev] Security Vunerability in SqueakSource

2011-03-21 Thread Sven Van Caekenberghe
On 21 Mar 2011, at 11:20, Bert Freudenberg wrote: > SqueakSource is simply a WebDAV server. All the versioning logic is local, > implemented in Monticello, so allowing overwrites is not really > SqueakSource's "fault". Besides, even if SqueakSource disallowed overwriting > a version (which it

Re: [Pharo-project] [squeak-dev] Security Vunerability in SqueakSource

2011-03-21 Thread Marcus Denker
On Mar 21, 2011, at 12:23 PM, Sven Van Caekenberghe wrote: > > On 21 Mar 2011, at 11:20, Bert Freudenberg wrote: > >> SqueakSource is simply a WebDAV server. All the versioning logic is local, >> implemented in Monticello, so allowing overwrites is not really >> SqueakSource's "fault". Beside

Re: [Pharo-project] [squeak-dev] Security Vunerability in SqueakSource

2011-03-21 Thread Bert Freudenberg
On 21.03.2011, at 12:40, Marcus Denker wrote: > > On Mar 21, 2011, at 12:23 PM, Sven Van Caekenberghe wrote: > >> >> On 21 Mar 2011, at 11:20, Bert Freudenberg wrote: >> >>> SqueakSource is simply a WebDAV server. All the versioning logic is local, >>> implemented in Monticello, so allowing