[Bug 884910] Re: Security issue (no CVE yet)

2011-11-24 Thread Bug Watch Updater
** Changed in: python-django-piston (Debian) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage notifications about

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-09 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/maverick-security/python-django-piston ** Branch linked: lp:ubuntu/oneiric-security/python-django-piston ** Branch linked: lp:ubuntu/natty-security/python-django-piston -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-09 Thread Launchpad Bug Tracker
This bug was fixed in the package python-django-piston - 0.2.2-1ubuntu0.2 --- python-django-piston (0.2.2-1ubuntu0.2) maverick-security; urgency=low * SECURITY UPDATE: remote code execution vulnerability. LP: #884910 - 02-fix-yaml-load.diff: use yaml.safe_load - 03-fix-pickl

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-09 Thread Launchpad Bug Tracker
This bug was fixed in the package python-django-piston - 0.2.2-1ubuntu1.11.04.1 --- python-django-piston (0.2.2-1ubuntu1.11.04.1) natty-security; urgency=low * SECURITY UPDATE: remote code execution vulnerability. LP: #884910 - 02-fix-yaml-load.diff: use yaml.safe_load - 03-

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-09 Thread Launchpad Bug Tracker
This bug was fixed in the package python-django-piston - 0.2.2-1ubuntu1.11.10.1 --- python-django-piston (0.2.2-1ubuntu1.11.10.1) oneiric-security; urgency=low * SECURITY UPDATE: remote code execution vulnerability. LP: #884910 - 02-fix-yaml-load.diff: use yaml.safe_load - 0

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-09 Thread Jamie Strandboge
Thanks for your patches! A few notes: CVE-2011-4103 has been assigned to this issue, so I added it to the changelogs. The maverick debdiff did not apply because the UDD tree you pulled from did not include the changes made to the maverick-updates package. I have applied your changes and created a

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-09 Thread Jamie Strandboge
0.2.2-2 is in Precise, which contains the fix. ** Also affects: python-django-piston (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: python-django-piston (Ubuntu Natty) Importance: Undecided Status: New ** Also affects: python-django-piston (Ubuntu Oneiri

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Tyler Hicks
Subscribing ubuntu-security-sponsors -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage notifications about this bug go to: https://bugs.launchpad.net

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Julian Taylor
precise can be synced when it is uploaded to debian, we don't need the diff anymore -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage notifications a

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Julian Taylor
** Changed in: python-django-piston (Ubuntu) Assignee: Julian Taylor (jtaylor) => (unassigned) ** Changed in: python-django-piston (Ubuntu) Status: In Progress => Triaged ** Changed in: python-django-piston (Ubuntu) Status: Triaged => Fix Committed -- You received this bug no

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Launchpad Bug Tracker
** Branch linked: lp:~jtaylor/ubuntu/maverick/python-django- piston/fix-884910 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage notifications about

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Julian Taylor
** Branch unlinked: lp:~jtaylor/ubuntu/maverick/python-django- piston/fix-884910 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage notifications abou

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Launchpad Bug Tracker
** Branch linked: lp:~jtaylor/ubuntu/natty/python-django- piston/fix-884910 ** Branch linked: lp:~jtaylor/ubuntu/oneiric/python-django- piston/fix-884910 ** Branch linked: lp:~jtaylor/ubuntu/maverick/python-django- piston/fix-884910 -- You received this bug notification because you are a member

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-02 Thread Julian Taylor
** Changed in: python-django-piston (Ubuntu) Importance: Undecided => High ** Changed in: python-django-piston (Ubuntu) Assignee: (unassigned) => Julian Taylor (jtaylor) ** Changed in: python-django-piston (Ubuntu) Status: New => In Progress -- You received this bug notification

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-01 Thread Bug Watch Updater
** Changed in: python-django-piston (Debian) Importance: Undecided => Unknown -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage notifications abou

[Bug 884910] Re: Security issue (no CVE yet)

2011-11-01 Thread Julian Taylor
another security issue in the package: http://bugs.debian.org/cgi- bin/bugreport.cgi?bug=646517 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/884910 Title: Security issue (no CVE yet) To manage not