Your message dated Sun, 19 Aug 2007 21:47:04 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#435912: fixed in nspluginwrapper 0.9.91.4-4
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: nspluginwrapper
Version: 0.9.91.4-3
Severity: normal

I have iceape with nspluginwrapper and Adobe 32-bit flash plugin 
installed on my debian-amd64/unstable system. I've just noticed that 
even when a flash application is running inside iceape browser that is 
NOT currently active window, it is still receiving all the keystokes and 
responding to them. 
I believe this is a security hole as this opens a possibilty to 
a flash application to spy on you (e.g., when you are typing a password 
for some other application).
Also, as I am unable to reproduce this bug with debian-i386/unstable and 
Adobe flash plugin, I believe this bug is somehow related to nspluginwrapper 
used on debian-amd64. If it is not related to nspluginwrapper, please 
forward this bugreport accordingly.

To reproduce this bug:

1) Run iceape and load this page:
http://www.addictinggames.com/bloxors.html

2) You will see a (nice) flash game. Start a new game there and proceed 
to Stage 1. Note that the game is controlled by the arrows keys on the 
keyboard.

3) Now, switch to other application (e.g., run a text editor) and 
try to press arrow keys there. You will see that the flash game is still 
responding to these keys, meaning that it gets the keystrokes that are 
supposed to have an effect in this other application only.
 

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'sarge-unsupported'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.22.1 (SMP w/2 CPU cores)
Locale: LANG=ru_RU.KOI8-R, LC_CTYPE=ru_RU.KOI8-R (charmap=KOI8-R)
Shell: /bin/sh linked to /bin/bash

Versions of packages nspluginwrapper depends on:
ii  fake-ia32-libs [ia32-libs]    1.0        Fake ia32-libs
ii  ia32-libs                     2.1        ia32 shared libraries for use on a
ii  ia32-libs-gtk                 2.0        gtk+ ia32 shared libraries
ii  lib32gcc1                     1:4.2.1-1  GCC support library (32 bit Versio
ii  libc6                         2.6-5      GNU C Library: Shared libraries
ii  libc6-i386                    2.6-5      GNU C Library: 32bit shared librar
ii  libglib2.0-0                  2.12.13-1  The GLib library of C routines
ii  libx11-6                      2:1.0.3-7  X11 client-side library
ii  libxt6                        1:1.0.5-3  X11 toolkit intrinsics library
ii  linux32                       1-3        Wrapper to set the execution domai

nspluginwrapper recommends no packages.

-- debconf-show failed


--- End Message ---
--- Begin Message ---
Source: nspluginwrapper
Source-Version: 0.9.91.4-4

We believe that the bug you reported is fixed in the latest version of
nspluginwrapper, which is due to be installed in the Debian FTP archive:

nspluginwrapper_0.9.91.4-4.diff.gz
  to pool/contrib/n/nspluginwrapper/nspluginwrapper_0.9.91.4-4.diff.gz
nspluginwrapper_0.9.91.4-4.dsc
  to pool/contrib/n/nspluginwrapper/nspluginwrapper_0.9.91.4-4.dsc
nspluginwrapper_0.9.91.4-4_amd64.deb
  to pool/contrib/n/nspluginwrapper/nspluginwrapper_0.9.91.4-4_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Rob Andrews <[EMAIL PROTECTED]> (supplier of updated nspluginwrapper package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 19 Aug 2007 20:17:33 +0100
Source: nspluginwrapper
Binary: nspluginwrapper
Architecture: source amd64
Version: 0.9.91.4-4
Distribution: unstable
Urgency: low
Maintainer: Rob Andrews <[EMAIL PROTECTED]>
Changed-By: Rob Andrews <[EMAIL PROTECTED]>
Description: 
 nspluginwrapper - A wrapper to run Netscape plugins on other architectures
Closes: 435912
Changes: 
 nspluginwrapper (0.9.91.4-4) unstable; urgency=low
 .
   * Change Priority: extra to "optional"
   * Add patch 002_install_to_NSPLUGINDIR.patch from Ubuntu
     (thanks Alexander Sack)
   * Fix XEmbed issue where plugin was able to grab keystrokes
     from other applications when browser had lost focus
     - patch is 003_fix_xembed_grab_keys.diff
     (Closes: #435912)
Files: 
 8c50adbe789134b869d06dd8a917bd23 835 contrib/utils optional 
nspluginwrapper_0.9.91.4-4.dsc
 66f706a93567a8f578669339b4acae08 10573 contrib/utils optional 
nspluginwrapper_0.9.91.4-4.diff.gz
 8bdef54f5c9cd3564ad7af3d45f398fe 102300 contrib/utils optional 
nspluginwrapper_0.9.91.4-4_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGyLkAIae1O4AJae8RAj4RAJ0VC6Y4Y9YWIySZlLiWjVHZ4Q/FTQCfRsNi
GNZ7qmTyW17n5iI5kj4SJ9w=
=oJ4B
-----END PGP SIGNATURE-----


--- End Message ---

Reply via email to