Your message dated Thu, 01 Mar 2007 15:02:26 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#409703: fixed in sql-ledger 2.6.22-2
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: sql-ledger
Version: 2.6.22-1
Severity: important
Tags: security

Hi.
Maybe sql-ledger is affected by CVE-2007-0667.

Description:
Separate from CVE-2006-5872, there is a possibility of causing arbitrary
code execution during redirects. This requires a valid login to exploit
and was discovered and brought to the attention of both the SQL-Ledger
and LedgerSMB team in November. LedgerSMB 1.1.5 corred the problem, but
it is still not corrected in SQL-Ledger.

Reference:
http://www.frsirt.com/english/advisories/2007/0407
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0667

Note:
Please mention the CVE id in the changelog.


Thanks in advanced.


regards,
--
   .''`.
  : :' :    Alex de Oliveira Silva | enerv
  `. `'     www.enerv.net
    `-


--- End Message ---
--- Begin Message ---
Source: sql-ledger
Source-Version: 2.6.22-2

We believe that the bug you reported is fixed in the latest version of
sql-ledger, which is due to be installed in the Debian FTP archive:

sql-ledger_2.6.22-2.diff.gz
  to pool/main/s/sql-ledger/sql-ledger_2.6.22-2.diff.gz
sql-ledger_2.6.22-2.dsc
  to pool/main/s/sql-ledger/sql-ledger_2.6.22-2.dsc
sql-ledger_2.6.22-2_all.deb
  to pool/main/s/sql-ledger/sql-ledger_2.6.22-2_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Raphael Hertzog <[EMAIL PROTECTED]> (supplier of updated sql-ledger package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Thu,  1 Mar 2007 15:34:36 +0100
Source: sql-ledger
Binary: sql-ledger
Architecture: source all
Version: 2.6.22-2
Distribution: unstable
Urgency: high
Maintainer: Finn-Arne Johansen <[EMAIL PROTECTED]>
Changed-By: Raphael Hertzog <[EMAIL PROTECTED]>
Description: 
 sql-ledger - A web based double-entry accounting program
Closes: 409703
Changes: 
 sql-ledger (2.6.22-2) unstable; urgency=high
 .
   * Document the security problem of SQL-Ledger in the README.Debian file
     (and in NEWS). Closes: #409703
Files: 
 087dec9c5e83d07b458a7e06855e12a5 706 web optional sql-ledger_2.6.22-2.dsc
 a3ba2cb155fe830efddd3ee28a0bbdc2 13703 web optional sql-ledger_2.6.22-2.diff.gz
 6522fb8820fb31996615537e550a7362 2798738 web optional 
sql-ledger_2.6.22-2_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF5ubtvPbGD26BadIRAgCDAJ9Q1TEbnptR/cvgYkWSHRtUorJ9eACeMxv6
zcSEzGxCZ4P/ODRV5o9fLLU=
=8Un5
-----END PGP SIGNATURE-----


--- End Message ---

Reply via email to