Your message dated Thu, 20 Jan 2005 19:47:12 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#291433: fixed in sword 1.5.7-7
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 20 Jan 2005 18:41:19 +0000
>From [EMAIL PROTECTED] Thu Jan 20 10:41:19 2005
Return-path: <[EMAIL PROTECTED]>
Received: from kitenet.net [64.62.161.42] (postfix)
        by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
        id 1CrhF9-0002nF-00; Thu, 20 Jan 2005 10:41:19 -0800
Received: from dragon.kitenet.net (unknown [66.168.94.144])
        (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
        (Client CN "Joey Hess", Issuer "Joey Hess" (verified OK))
        by kitenet.net (Postfix) with ESMTP id 7757F180AD
        for <[EMAIL PROTECTED]>; Thu, 20 Jan 2005 18:41:17 +0000 (GMT)
Received: by dragon.kitenet.net (Postfix, from userid 1000)
        id CD9CD6E6B7; Thu, 20 Jan 2005 13:43:21 -0500 (EST)
Date: Thu, 20 Jan 2005 13:43:20 -0500
From: Joey Hess <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: FWD: [SECURITY] [DSA 650-1] New sword packages fix arbitrary command 
execution
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
        protocol="application/pgp-signature"; boundary="9jxsPFA5p3P2qPhR"
Content-Disposition: inline
User-Agent: Mutt/1.5.6+20040907i
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 


--9jxsPFA5p3P2qPhR
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Package: sword
Version: 1.5.7-6
Tags: security
Severity: grave

The DSA below talks about a new version of sword being forthcoing for
sid, but I don't see it in the queue or archive, so I'm filing this bug
to make sure we don't forget to do it. If you have in fact already
finished a build or something, feel free to close this bug report.

----- Forwarded message from Martin Schulze <[EMAIL PROTECTED]> -----

=46rom: Martin Schulze <[EMAIL PROTECTED]>
Date: Thu, 20 Jan 2005 17:07:38 +0100 (CET)
To: Debian Security Announcements <[EMAIL PROTECTED]
g>
Subject: [SECURITY] [DSA 650-1] New sword packages fix arbitrary command ex=
ecution
User-Agent: dsa-launch $Revision: 1.15 $
Reply-To: debian-security@lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 650-1                     [EMAIL PROTECTED]
http://www.debian.org/security/                             Martin Schulze
January 20th, 2005                         http://www.debian.org/security/f=
aq
- --------------------------------------------------------------------------

Package        : sword
Vulnerability  : missing input sanitising
Problem-Type   : remote
Debian-specific: no
CVE ID         : CAN-2005-0015

Ulf H=E4rnhammar discovered that due to missing input sanitising in
diatheke, a CGI script for making and browsing a bible website, it is
possible to execute arbitrary commands via a specially crafted URL.

For the stable distribution (woody) this problem has been fixed in
version 1.5.3-3woody2.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your diatheke package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/s/sword/sword_1.5.3-3woody=
2.dsc
      Size/MD5 checksum:      612 9204579e3a264d7d43297c1b7bf98438
    http://security.debian.org/pool/updates/main/s/sword/sword_1.5.3-3woody=
2.diff.gz
      Size/MD5 checksum:    21169 c355f97deb2ef2c39b82aec857b15a21
    http://security.debian.org/pool/updates/main/s/sword/sword_1.5.3.orig.t=
ar.gz
      Size/MD5 checksum:  2389613 055f9c1e7c081a667674d9f4112abf11

  Alpha architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_alpha.deb
      Size/MD5 checksum:    82154 2c73838e4e5d1112ded21365df2578a3
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_alpha.deb
      Size/MD5 checksum:  1712920 e3914e31b0b0217ac8f227f8730c0ace
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_alpha.deb
      Size/MD5 checksum:    13312 29c89888a4b51b5aa555ff55b0a410ad
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_alpha.deb
      Size/MD5 checksum:   601828 dfcf6f97b2b3eead528e92b5dc387fe6

  ARM architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_arm.deb
      Size/MD5 checksum:    56756 0a83537894f73c59aac38b8698d68dc8
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_arm.deb
      Size/MD5 checksum:   989694 18f31fc2d82aec5b342a62822f6421d8
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_arm.deb
      Size/MD5 checksum:    13326 f8a405bc39b9e73d84cb42448144b4ec
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_arm.deb
      Size/MD5 checksum:   298826 53df2455c33de26ddc7f661f1ff74a43

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_i386.deb
      Size/MD5 checksum:    54788 7329737ccfe2988b667bf1cf4d0b684d
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_i386.deb
      Size/MD5 checksum:   923510 87cbc45e59453e36004331d8a1ba4950
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_i386.deb
      Size/MD5 checksum:    13320 190147bb90a295003c9bf6ad0e0a48d4
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_i386.deb
      Size/MD5 checksum:   281460 c0c5beeb00046e67a6fa9089e9d43d14

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_ia64.deb
      Size/MD5 checksum:    62174 fbf8fac6dfc7d61a739b3bdb3f499566
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_ia64.deb
      Size/MD5 checksum:  1291474 d38e91788454487c3fc8b40e017fc682
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_ia64.deb
      Size/MD5 checksum:    13308 b24742b3c41724e34669d0b921cb3d27
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_ia64.deb
      Size/MD5 checksum:   333424 7aaaaf076026a95ac0d0bdbe488777fb

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_hppa.deb
      Size/MD5 checksum:    62118 2504df74d92b6adb4910a6a4f3452183
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_hppa.deb
      Size/MD5 checksum:  1104178 07328cd8ee7dde27dfed04296e3ae908
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_hppa.deb
      Size/MD5 checksum:    13320 d62ee10092df4e13ad703662fd5ffdda
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_hppa.deb
      Size/MD5 checksum:   321394 ab1a13bf24f55ca743a8c760adebc8e9

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_m68k.deb
      Size/MD5 checksum:    53082 39829e678361864e1da30406d34b63eb
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_m68k.deb
      Size/MD5 checksum:   932564 a1189885065e93581e8467cc85b270cd
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_m68k.deb
      Size/MD5 checksum:    13340 2b3407e4e1f8e272f86d297d6ff73738
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_m68k.deb
      Size/MD5 checksum:   298670 47ec4a13a6a9492deaa50d841366458d

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_mips.deb
      Size/MD5 checksum:    52350 e4c719c9a0dda7691232f30eef22dbde
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_mips.deb
      Size/MD5 checksum:  1109974 878366a171bca33b56ee9710119412c9
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_mips.deb
      Size/MD5 checksum:    13332 91fe931443f5ae22621628db2deef543
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_mips.deb
      Size/MD5 checksum:   256508 82fb17f0ff951a96d406d1f65eac8a26

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_mipsel.deb
      Size/MD5 checksum:    52126 5e61bca3b51666582fbb182398f0f9bd
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_mipsel.deb
      Size/MD5 checksum:  1099316 5de4d4a7a89bc24bb3e50f4bf6edf740
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_mipsel.deb
      Size/MD5 checksum:    13346 f0fcbee29448cd9c32d906ecdee962f3
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_mipsel.deb
      Size/MD5 checksum:   240420 b71294049ac28ea1fafe85968b6499de

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_powerpc.deb
      Size/MD5 checksum:    53026 4063714e63bb48f93c16c70be949d2c1
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_powerpc.deb
      Size/MD5 checksum:  1000066 7eda6d983cd89dee3543b6db26a3bdfe
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_powerpc.deb
      Size/MD5 checksum:    13318 3687a1d751652c987d9e658463e71e9a
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_powerpc.deb
      Size/MD5 checksum:   306722 8d01c00d9235925512c46b5e4efe5bfe

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_s390.deb
      Size/MD5 checksum:    50260 6dafccc1e39907a9852bb8f73be90c30
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_s390.deb
      Size/MD5 checksum:   889972 dc0a114eb6df20568623173363c34fab
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_s390.deb
      Size/MD5 checksum:    13322 520de046e8134166d87d0ea4eb699d1f
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_s390.deb
      Size/MD5 checksum:   278278 9fcd920f31203c18884a74d3e2b208ad

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3wo=
ody2_sparc.deb
      Size/MD5 checksum:    53248 ed0cafc23539322dd589c13d74fef525
    http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5.3=
-3woody2_sparc.deb
      Size/MD5 checksum:   953876 862ce2d7c89eeb445a1348158439838f
    http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_1=
=2E5.3-3woody2_sparc.deb
      Size/MD5 checksum:    13322 d7db9daeb609981e322caa1549b84015
    http://security.debian.org/pool/updates/main/s/sword/libsword1_1.5.3-3w=
oody2_sparc.deb
      Size/MD5 checksum:   281526 2d918e10ef4eba590d5185410e11340d


  These files will probably be moved into the stable distribution on
  its next update.

- -------------------------------------------------------------------------=
--------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/update=
s/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFB79dHW5ql+IAeqTIRAv83AJ9edTzwp8lcwzBU9z/IDhFU+47YCQCdEfg+
QsLqO8u8pblK3827Zf3iIGw=3D
=3DS0pH
-----END PGP SIGNATURE-----


--=20
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
rg


----- End forwarded message -----
--=20
see shy jo

--9jxsPFA5p3P2qPhR
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFB7/vId8HHehbQuO8RAtTiAJoCSfVOEQDKDDIwsE/hBvOnIeUelwCfYXWQ
upLrS6fwq9/lquvwZI5J4Vs=
=tlO2
-----END PGP SIGNATURE-----

--9jxsPFA5p3P2qPhR--

---------------------------------------
Received: (at 291433-close) by bugs.debian.org; 21 Jan 2005 00:53:02 +0000
>From [EMAIL PROTECTED] Thu Jan 20 16:53:02 2005
Return-path: <[EMAIL PROTECTED]>
Received: from newraff.debian.org [208.185.25.31] (mail)
        by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
        id 1Crn2s-0002TT-00; Thu, 20 Jan 2005 16:53:02 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
        id 1CrmxE-0005VG-00; Thu, 20 Jan 2005 19:47:12 -0500
From: Daniel Glassey <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.55 $
Subject: Bug#291433: fixed in sword 1.5.7-7
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Thu, 20 Jan 2005 19:47:12 -0500
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Source: sword
Source-Version: 1.5.7-7

We believe that the bug you reported is fixed in the latest version of
sword, which is due to be installed in the Debian FTP archive:

diatheke_1.5.7-7_i386.deb
  to pool/main/s/sword/diatheke_1.5.7-7_i386.deb
libsword-dev_1.5.7-7_i386.deb
  to pool/main/s/sword/libsword-dev_1.5.7-7_i386.deb
libsword4_1.5.7-7_i386.deb
  to pool/main/s/sword/libsword4_1.5.7-7_i386.deb
sword_1.5.7-7.diff.gz
  to pool/main/s/sword/sword_1.5.7-7.diff.gz
sword_1.5.7-7.dsc
  to pool/main/s/sword/sword_1.5.7-7.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Glassey <[EMAIL PROTECTED]> (supplier of updated sword package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Mon, 17 Jan 2005 16:24:37 +0000
Source: sword
Binary: libsword4 libsword-dev diatheke
Architecture: source i386
Version: 1.5.7-7
Distribution: unstable
Urgency: high
Maintainer: Daniel Glassey <[EMAIL PROTECTED]>
Changed-By: Daniel Glassey <[EMAIL PROTECTED]>
Description: 
 diatheke   - CGI script for making bible website
 libsword-dev - Development files for libsword
 libsword4  - API/library for bible software
Closes: 291433
Changes: 
 sword (1.5.7-7) unstable; urgency=high
 .
   * Patch from security team, Closes: #291433
   * Added shell_escape() function to fix arbitrary command execution
     [apps/console/diatheke/cgi/diatheke.pl, CAN-2005-0015]
   * Improvements by Ulf Härnhammar
Files: 
 1552e941332a7129ff3e0b88fcce4930 634 libs optional sword_1.5.7-7.dsc
 b16a270c05d11517358aeb80b862ce04 277082 libs optional sword_1.5.7-7.diff.gz
 48fb598e092df87d95cdd1e7553b3f5b 387794 libs optional 
libsword4_1.5.7-7_i386.deb
 f670f9288b4a39d11b83c0904de933dc 556608 libdevel optional 
libsword-dev_1.5.7-7_i386.deb
 21aa6d07784fc5fdad657e3a605dcdb7 57950 web optional diatheke_1.5.7-7_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFB8DUe/offrSwPzRoRAhbgAJ92gNOwfVuod71jRjmKqceDanZM9QCfeJ9Q
hz6pLTV3NmqKSX+JH7I8pRw=
=4XTc
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to