Your message dated Sat, 19 Feb 2005 13:02:28 -0500 with message-id <[EMAIL PROTECTED]> and subject line Bug#295971: fixed in jpilot 0.99.7-0.99.8-pre8-1 has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 19 Feb 2005 12:20:34 +0000 >From [EMAIL PROTECTED] Sat Feb 19 04:20:33 2005 Return-path: <[EMAIL PROTECTED]> Received: from ns2.spitfire.net (spitfire.net) [207.250.1.5] by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1D2Tb7-0005rB-00; Sat, 19 Feb 2005 04:20:33 -0800 Received: from pyromaniacs.hopto.org [66.90.224.235] by spitfire.net with ESMTP (SMTPD32-8.05) id A0CA9DC900E4; Sat, 19 Feb 2005 07:27:54 -0500 Received: from chris by pyromaniacs.hopto.org with local (Exim 4.34) id 1D2TbP-0001Jk-T1; Sat, 19 Feb 2005 07:20:51 -0500 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Chris Howie <[EMAIL PROTECTED]> To: Debian Bug Tracking System <[EMAIL PROTECTED]> Subject: jpilot: Hidden records can be viewed/modified without password X-Mailer: reportbug 2.63 Date: Sat, 19 Feb 2005 07:20:48 -0500 Message-Id: <[EMAIL PROTECTED]> Sender: Chris Howie <[EMAIL PROTECTED]> Delivered-To: [EMAIL PROTECTED] X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-4.3 required=4.0 tests=BAYES_00,FORGED_YAHOO_RCVD, HAS_PACKAGE autolearn=no version=2.60-bugs.debian.org_2005_01_02 X-Spam-Level: Package: jpilot Version: 0.99.7-0.99.8-pre7-1 Severity: grave Justification: user security hole In the main jpilot window, if the padlock button is pressed while private records are hidden or masked, and the cancel button is pressed (or the dialog is closed by the window manager) then private records will be unhidden. This may need to be done more than once, but it will eventually happen. This problem does not affect the "Show Private Records" menu item. -- System Information: Debian Release: 3.1 APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Kernel: Linux 2.6.8-1-686 Locale: LANG=C, LC_CTYPE=C Versions of packages jpilot depends on: ii debconf 1.4.30.8 Debian configuration management sy ii libatk1.0-0 1.8.0-4 The ATK accessibility toolkit ii libc6 2.3.2.ds1-18 GNU C Library: Shared libraries an ii libglib2.0-0 2.6.1-3 The GLib library of C routines ii libgtk2.0-0 2.4.13-1 The GTK+ graphical user interface ii libpango1.0-0 1.6.0-3 Layout and rendering of internatio ii libpisock8 0.11.8-10 Library for communicating with a P -- debconf information: * shared/pilot/port: None --------------------------------------- Received: (at 295971-close) by bugs.debian.org; 19 Feb 2005 18:08:25 +0000 >From [EMAIL PROTECTED] Sat Feb 19 10:08:24 2005 Return-path: <[EMAIL PROTECTED]> Received: from newraff.debian.org [208.185.25.31] (mail) by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1D2Z1k-0007z3-00; Sat, 19 Feb 2005 10:08:24 -0800 Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian)) id 1D2Yw0-0002gE-00; Sat, 19 Feb 2005 13:02:28 -0500 From: Ludovic Rousseau <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] X-Katie: $Revision: 1.55 $ Subject: Bug#295971: fixed in jpilot 0.99.7-0.99.8-pre8-1 Message-Id: <[EMAIL PROTECTED]> Sender: Archive Administrator <[EMAIL PROTECTED]> Date: Sat, 19 Feb 2005 13:02:28 -0500 Delivered-To: [EMAIL PROTECTED] X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER autolearn=no version=2.60-bugs.debian.org_2005_01_02 X-Spam-Level: X-CrossAssassin-Score: 3 Source: jpilot Source-Version: 0.99.7-0.99.8-pre8-1 We believe that the bug you reported is fixed in the latest version of jpilot, which is due to be installed in the Debian FTP archive: jpilot-plugins_0.99.7-0.99.8-pre8-1_i386.deb to pool/main/j/jpilot/jpilot-plugins_0.99.7-0.99.8-pre8-1_i386.deb jpilot_0.99.7-0.99.8-pre8-1.diff.gz to pool/main/j/jpilot/jpilot_0.99.7-0.99.8-pre8-1.diff.gz jpilot_0.99.7-0.99.8-pre8-1.dsc to pool/main/j/jpilot/jpilot_0.99.7-0.99.8-pre8-1.dsc jpilot_0.99.7-0.99.8-pre8-1_i386.deb to pool/main/j/jpilot/jpilot_0.99.7-0.99.8-pre8-1_i386.deb jpilot_0.99.7-0.99.8-pre8.orig.tar.gz to pool/main/j/jpilot/jpilot_0.99.7-0.99.8-pre8.orig.tar.gz A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [EMAIL PROTECTED], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Ludovic Rousseau <[EMAIL PROTECTED]> (supplier of updated jpilot package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [EMAIL PROTECTED]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 19 Feb 2005 18:04:34 +0100 Source: jpilot Binary: jpilot-plugins jpilot Architecture: source i386 Version: 0.99.7-0.99.8-pre8-1 Distribution: unstable Urgency: high Maintainer: Ludovic Rousseau <[EMAIL PROTECTED]> Changed-By: Ludovic Rousseau <[EMAIL PROTECTED]> Description: jpilot - graphical app. to modify the contents of your Palm Pilot's DBs jpilot-plugins - plugins for jpilot (Palm Pilot desktop) Closes: 278635 293004 295971 Changes: jpilot (0.99.7-0.99.8-pre8-1) unstable; urgency=high . * urgency=high since this version correct security bug #295971 * new upstream version - Closes: #295971 "Hidden records can be viewed/modified without password" - Closes: #278635 "cut and paste does not works if you switch from memo to the phonebook" * add debconf Czech translation. Closes: #293004 Files: 82f01fe2b6c877db79d2e68db4c7b0e7 782 otherosfs extra jpilot_0.99.7-0.99.8-pre8-1.dsc f96b1bedc3179ae4a91502c6a782c8c8 1380605 otherosfs extra jpilot_0.99.7-0.99.8-pre8.orig.tar.gz fbbb37df3abbdc0551a7dd1e7a923642 16522 otherosfs extra jpilot_0.99.7-0.99.8-pre8-1.diff.gz 6f2289018697355afcd754211f757971 716720 otherosfs extra jpilot_0.99.7-0.99.8-pre8-1_i386.deb 2658420882a82251b5b913b501bc4794 48124 otherosfs extra jpilot-plugins_0.99.7-0.99.8-pre8-1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQFCF3sDP0qKj+B/HPkRAh7uAJ9SUeNm1PktmQjWMapWHfTbqMg84QCghJYS rBgyuN3yNGbwaVN3KAaGWh8= =m+M5 -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]