[Bug 607297] Re: vulnerability: rewrite arbitrary user file

2011-02-20 Thread Launchpad Bug Tracker
This bug was fixed in the package tesseract - 2.04-2.1 --- tesseract (2.04-2.1) unstable; urgency=low * Non-maintainer upload. * Bump build-dependency on quilt to >= 0.46-7~. * Disable xterm-based debug windows (closes: #612032, LP: #607297). Thanks to Kees Cook for the bug

[Bug 607297] Re: vulnerability: rewrite arbitrary user file

2011-02-11 Thread Launchpad Bug Tracker
** Branch linked: lp:debian/tesseract -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/607297 Title: vulnerability: rewrite arbitrary user file -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.co

[Bug 607297] Re: vulnerability: rewrite arbitrary user file

2011-02-11 Thread Bug Watch Updater
** Changed in: tesseract (Debian) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/607297 Title: vulnerability: rewrite arbitrary user file -- ubuntu-bugs mailing l

[Bug 607297] Re: vulnerability: rewrite arbitrary user file

2011-02-06 Thread Bug Watch Updater
** Changed in: tesseract (Debian) Status: Unknown => New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/607297 Title: vulnerability: rewrite arbitrary user file -- ubuntu-bugs mailing list u

[Bug 607297] Re: vulnerability: rewrite arbitrary user file

2011-02-04 Thread Kees Cook
** Bug watch added: Debian Bug tracker #612032 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612032 ** Also affects: tesseract (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612032 Importance: Unknown Status: Unknown -- You received this bug notification because

[Bug 607297] Re: vulnerability: rewrite arbitrary user file

2011-02-04 Thread Kees Cook
Thanks for taking the time to report this bug and helping to make Ubuntu better. The latest release of Ubuntu is not vulnerable to symlink race attacks, but earlier releases will need fixing. https://wiki.ubuntu.com/Security/Features#symlink Since the package referred to in this bug is in univers