[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2015-05-03 Thread dino99
Support for this version has ended ** Changed in: python2.4 (Ubuntu) Status: Confirmed => Invalid ** Changed in: python2.5 (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bu

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
python2.6 was fixed in 2.6.6-5ubuntu1. ** Changed in: python2.6 (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untrusted search path v

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
This was fixed in 0.96.1-7.1. ** Changed in: dia (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untrusted search path vulnerability in

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
vim was fixed in 2:7.2.079-1ubuntu5 ** Changed in: vim (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untrusted search path vulnerabil

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
nautilus-python was fixed in 0.6.1-1 ** Changed in: nautilus-python (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untrusted search pa

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
epiphany-browser was fixed in 2.24.1-0ubuntu1. ** Changed in: epiphany-browser (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untruste

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
eog was fixed in 2.24.1-0ubuntu1. ** Changed in: eog (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untrusted search path vulnerabilit

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2011-04-27 Thread Jamie Strandboge
csound was fixed in 1:5.08.2~dfsg-1.1ubuntu2. ** Changed in: csound (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/322196 Title: Untrusted search pa

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-09-15 Thread Bug Watch Updater
** Changed in: gedit Importance: Unknown => Medium -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mai

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-07-23 Thread Bug Watch Updater
** Changed in: gedit Status: New => Fix Released -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs m

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-07 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/hardy-security/xchat -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-07 Thread Launchpad Bug Tracker
This bug was fixed in the package xchat - 2.8.4-0ubuntu7.1 --- xchat (2.8.4-0ubuntu7.1) hardy-security; urgency=low * SECURITY UPDATE (LP: #322196) * debian/patches/64_CVE-2009-0315.dpatch: - Fix untrusted search path vulnerability in the Python module in xchat allows lo

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-07 Thread Marc Deslauriers
ACK on the hardy update. Updated package was uploaded to hardy-security. Thanks for the debdiff. ** Changed in: xchat (Ubuntu) Status: Confirmed => Fix Committed -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You receive

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-03 Thread Bug Watch Updater
** Changed in: python Status: Unknown => Fix Released -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-b

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-03 Thread Jan Claeys
** Also affects: python via http://bugs.python.org/issue5753 Importance: Unknown Status: Unknown -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu B

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-03 Thread Jan Claeys
Upstream python has committed an alternative PySys_SetArgvEx that allows applications that embed python to set sys.argv without also modifying sys.path: http://bugs.python.org/issue5753#msg106256 It does require patches to all those applications though... ** Bug watch added: Python Roundup #5753

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-01 Thread Kees Cook
Shouldn't this be fixed in Python rather than all the tools using Python? -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-06-01 Thread Launchpad Bug Tracker
** Branch linked: lp:~ari-tczew/ubuntu/hardy/xchat/CVE-2009-0315 -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubun

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-05-30 Thread Artur Rona
** Description changed: There's an interesting bug (or feature?) in Python 2.6 and earlier that affects multiple applications using Python. The bug allows local or user-assisted remote arbitrary code execution. Here is the description of the Python CVE: "Untrusted search path vulnerab

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2010-03-04 Thread Andreas Guelzow
Note that a workaround to this python bug was committed to Gnumeric upstream a long time ago (2009-01-29) and so this vulnerability is not in gnumeric anymore since release 1.9.4. ** Changed in: gnumeric (Ubuntu) Status: Confirmed => Fix Released -- Untrusted search path vulnerability in

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-12-02 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/gedit -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bug

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-04-16 Thread Kees Cook
** Changed in: epiphany-browser (Ubuntu) Importance: Undecided => Low -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-04-08 Thread Launchpad Bug Tracker
This bug was fixed in the package gedit - 2.26.0-0ubuntu3 --- gedit (2.26.0-0ubuntu3) jaunty; urgency=low * debian/patches/91_correct_path_use.patch: - CVE-2009-0314, don't use an untrusted python path when loading (lp: #322196) -- Sebastien BacherWed, 08 Apr 2009 13

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-04-04 Thread Matthias Klose
** Also affects: python2.6 (Ubuntu) Importance: Undecided Status: New ** Changed in: python2.6 (Ubuntu) Importance: Undecided => Low ** Changed in: python2.6 (Ubuntu) Status: New => Confirmed ** Changed in: python2.3 (Ubuntu) Status: Confirmed => Won't Fix -- Untrust

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-03-09 Thread Bug Watch Updater
** Changed in: gedit Status: Unknown => New -- Untrusted search path vulnerability in Python and multiple other programs https://bugs.launchpad.net/bugs/322196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailin

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-02-12 Thread Sebastien Bacher
** Changed in: gedit (Ubuntu) Assignee: (unassigned) => Ubuntu Desktop Bugs (desktop-bugs) Status: Confirmed => Triaged ** Bug watch added: GNOME Bug Tracker #569214 http://bugzilla.gnome.org/show_bug.cgi?id=569214 ** Also affects: gedit via http://bugzilla.gnome.org/show_bug.cg

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-01-30 Thread Jamie Strandboge
** Changed in: epiphany (Ubuntu) Status: New => Invalid ** Also affects: epiphany-browser (Ubuntu) Importance: Undecided Status: New ** Also affects: python2.3 (Ubuntu) Importance: Undecided Status: New ** Changed in: epiphany-browser (Ubuntu) Status: New => Con

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-01-30 Thread Jamie Strandboge
** Changed in: csound (Ubuntu) Status: New => Confirmed ** Changed in: csound (Ubuntu) Importance: Undecided => Low ** Changed in: dia (Ubuntu) Status: New => Confirmed ** Changed in: dia (Ubuntu) Importance: Undecided => Low ** Changed in: eog (Ubuntu) Status: New =>

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-01-30 Thread Alexander Konovalenko
According to these links (provided by Jan Lieskovsky in the thread referenced above), Python 2.6 is affected as well. http://www.openwall.com/lists/oss-security/2009/01/28/5 https://bugzilla.redhat.com/show_bug.cgi?id=482814#c1 ** Description changed: - Binary package hint: python2.5 - - There'

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-01-27 Thread Alexander Konovalenko
Adding CVE references: CVE-2008-5983, CVE-2008-5984, CVE-2008-5985, CVE-2008-5986, CVE-2008-5987, CVE-2009-0314, CVE-2009-0315, CVE-2009-0316, CVE-2009-0317, CVE-2009-0318 ** Also affects: python2.4 (Ubuntu) Importance: Undecided Status: New ** Also affects: dia (Ubuntu) Importance