Package: uim
Severity: normal


Good day,

>From CAN-2005-0503 :

| uim before 0.4.5.1 trusts certain environment variables when libUIM is used in
| setuid or setgid applications, which allows local users to gain privileges.

This have been fixed in uim 0.4.5.1

More info is available here :

http://lists.freedesktop.org/archives/uim/2005-February/000996.html

Could you please include the CAN number in changelog entries about this bug?

Regards.

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.6.8-2-686
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15) (ignored: 
LC_ALL set to [EMAIL PROTECTED])


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to