Bug#508628: etch-backports still vulnerable

2009-01-19 Thread Holger Levsen
On Montag, 19. Januar 2009, Holger Levsen wrote: > I'm writing an announcement for bpo announce now and will then upload > 0.1.1-10~bpo to bpo. done signature.asc Description: This is a digitally signed message part.

Bug#508628: etch-backports still vulnerable

2009-01-19 Thread Holger Levsen
Hi Vincent, On Freitag, 16. Januar 2009, Vincent Bernat wrote: > In current version in bpo, there is a patch that allows to use older > version of php-mail-mimedecode. It should be better to use it. This is: > fix-too-old-php-mail-mime.patch Ah, thanks. That does the trick! :) I'm writing a

Bug#508628: etch-backports still vulnerable

2009-01-16 Thread Vincent Bernat
OoO En ce début d'après-midi ensoleillé du jeudi 15 janvier 2009, vers 15:34, Holger Levsen disait : > roundcube needs newer php-mail-mime, so I backported that. That needs newer > php-mail-mimedecode, which needs newer dh-make-php to build, so I backported > that too. In current version in b

Bug#508628: etch-backports still vulnerable

2009-01-16 Thread Holger Levsen
Hi, On Freitag, 16. Januar 2009, Florian Weimer wrote: > "-/package.xml" looks rather like an unset make variable in > debian/rules to me. You're right, thanks for the hint. I then built the package in lenny and saw the problem. debian/rules includes /usr/share/cdbs/1/class/pear.mk which contai

Bug#508628: etch-backports still vulnerable

2009-01-16 Thread Florian Weimer
* Holger Levsen: > install --nodeps -P > > ~/Software/roundcube/php-mail-mimedecode-1.5.0/debian/php-mail-mimedecode/ > -/package.xml > Console_Getopt: unrecognized option -- / > If I understand this correctly, it seems the syntax used is only ava

Bug#508628: etch-backports still vulnerable

2009-01-15 Thread Holger Levsen
Hi, On Donnerstag, 15. Januar 2009, Kalev Kadak wrote: > > to the roundcube maintainers: do you plan an upload to bpo? I have a > > backport ready (well, needs testing, but I'm about to do this) which I > > could upload... I was too fast: roundcube needs newer php-mail-mime, so I backported that

Bug#508628: etch-backports still vulnerable

2009-01-15 Thread Kalev Kadak
Holger Levsen wrote: Hi, On Dienstag, 13. Januar 2009, Kingsley Masters wrote: I'd like to comfirm this bug still exists on etch-backports and is being actively exploited. Our Debian server running roundcube was comprimised yesterday though this bug. Kingsley, out of curiosity, do yo

Bug#508628: etch-backports still vulnerable

2009-01-15 Thread Holger Levsen
Hi, On Dienstag, 13. Januar 2009, Kingsley Masters wrote: > I'd like to comfirm this bug still exists on etch-backports and is being > actively exploited. Our Debian server running roundcube was comprimised > yesterday though this bug. Kingsley, out of curiosity, do you have suhosin installed?

Bug#508628: etch-backports still vulnerable

2008-12-28 Thread Marco Solieri
Roundcube version in etch-backports is still to version 0.1-4~bpo40+1: it is still unpatched and vulnerable. Bug has been reopened. -- Marco Solieri aka SoujaK signature.asc Description: This is a digitally signed message part.