[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-12-03 Thread Ross Heflin
got the updated package in xubuntu gutsy and functionality of yarssr now appears broken... details and screenshots here: https://bugs.launchpad.net/ubuntu/+source/yarssr/+bug/172667 -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-26 Thread Kees Cook
** Changed in: yarssr (Ubuntu Edgy) Status: Fix Committed = Fix Released ** Changed in: yarssr (Ubuntu Dapper) Status: Fix Committed = Fix Released -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-19 Thread Kees Cook
** Changed in: yarssr (Ubuntu Dapper) Status: In Progress = Fix Committed ** Changed in: yarssr (Ubuntu Edgy) Status: In Progress = Fix Committed ** Changed in: yarssr (Ubuntu Feisty) Status: In Progress = Fix Committed ** Changed in: yarssr (Ubuntu Gutsy) Status: In

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-19 Thread Kees Cook
These looks great! I've uploaded them to the security queue; they should be published shortly. -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-19 Thread William Grant
yarssr (0.2.2-1ubuntu0.7.04) feisty-security; urgency=low * SECURITY UPDATE: code execution through malicious URLs (LP: #162351) * Add debian/patches/code-injection-fix.dpatch: Thanks to Debian. * References CVE-2007-5837 -- William Grant [EMAIL PROTECTED] Tue, 13 Nov 2007 18:40:38

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-19 Thread William Grant
yarssr (0.2.2-1ubuntu1.1) gutsy-security; urgency=low * SECURITY UPDATE: code execution through malicious URLs (LP: #162351) * Add debian/patches/code-injection-fix.dpatch: Thanks to Debian. * References CVE-2007-5837 -- William Grant [EMAIL PROTECTED] Tue, 13 Nov 2007 18:40:38

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-13 Thread William Grant
** Attachment added: gutsy debdiff http://launchpadlibrarian.net/10347685/gutsy.diff -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-13 Thread William Grant
** Attachment added: dapper debdiff http://launchpadlibrarian.net/10347667/dapper.diff -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-13 Thread William Grant
** Attachment added: feisty debdiff http://launchpadlibrarian.net/10347684/feisty.diff -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-13 Thread William Grant
** Attachment added: edgy debdiff http://launchpadlibrarian.net/10347669/edgy.diff -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-13 Thread Bug Watch Updater
** Changed in: yarssr (Debian) Status: Unknown = Fix Released -- CVE-2007-5837: Code injection through badly formatted URL https://bugs.launchpad.net/bugs/162351 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. --

[Bug 162351] Re: CVE-2007-5837: Code injection through badly formatted URL

2007-11-12 Thread William Grant
Fixed in Debian in 0.2.2-3, which we have in Hardy. ** Changed in: yarssr (Ubuntu Hardy) Importance: Undecided = High Status: New = Fix Released ** Changed in: yarssr (Ubuntu Gutsy) Importance: Undecided = High Status: New = Confirmed ** Changed in: yarssr (Ubuntu Feisty)