Bug#497640: zoneminder: Several security issues

2009-04-15 Thread Peter Howard
On Wed, 2009-04-15 at 21:33 +0200, Ansgar Burchardt wrote: > Hi, > > zoneminder 1.24.0 has been released in Februrary. Have you any plans to > update the Debian package yet? It would be nice if the security > problems could be fixed. I have (or had, see next para) a package for 1.24 but haven't

Bug#497640: zoneminder: Several security issues

2009-04-15 Thread Ansgar Burchardt
Hi, zoneminder 1.24.0 has been released in Februrary. Have you any plans to update the Debian package yet? It would be nice if the security problems could be fixed. Regards, Ansgar -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble

Bug#497640: zoneminder: Several security issues (XSS, SQL injection, Command injection)

2008-09-06 Thread Peter Howard
On Wed, 2008-09-03 at 19:54 +1000, Steffen Joeris wrote: > Package: zoneminder > Severity: grave > Tags: security > Justification: user security hole > > Hi, > the following CVE (Common Vulnerabilities & Exposures) ids were > published for zoneminder. > These are currently being fixed in the nex

Bug#497640: zoneminder: Several security issues (XSS, SQL injection, Command injection)

2008-09-03 Thread Steffen Joeris
Package: zoneminder Severity: grave Tags: security Justification: user security hole Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for zoneminder. CVE-2008-3882[0]: | ZoneMinder 1.23.3 and earlier allows remote attackers to execute | arbitrary commands (aka "Comman