Bug#533673: moin: hierarchical ACL behavior

2009-06-24 Thread Michael S. Gilbert
On Wed, 24 Jun 2009 22:41:35 +0200, Frank Lin PIAT wrote: > I couldn't find any announcement of such announcement on RedHat/Google. > Do you have some pointer? i was mistaken, it was the FSA that i was referring to (i tend to equate redhat and fedora). there have been no updates to redhat-propper

Bug#533673: moin: hierarchical ACL behavior

2009-06-24 Thread Frank Lin PIAT
On Wed, 2009-06-24 at 13:29 -0400, Michael S. Gilbert wrote: > On Sat, 20 Jun 2009 18:15:16 +0200, Frank Lin PIAT wrote: > > I have analyzed the code, and made some test. It seems that there is no > > such "ACL vulnerability". Actually it doesn't even seems to be a bug: > > The developers seems to

Bug#533673: moin: hierarchical ACL behavior

2009-06-24 Thread Michael S. Gilbert
On Sat, 20 Jun 2009 18:15:16 +0200, Frank Lin PIAT wrote: > I have analyzed the code, and made some test. It seems that there is no > such "ACL vulnerability". Actually it doesn't even seems to be a bug: > The developers seems to have decided to change the behavior of ACLs in > moinmoin: redhat di

Bug#533673: moin: hierarchical ACL behavior

2009-06-20 Thread Frank Lin PIAT
severity 533673 normal thanks On Fri, 2009-06-19 at 14:00 -0400, Michael S. Gilbert wrote: > > moin in stable/oldstable has a heirarchical ACL vulnerability. this > is fixed in upstream 1.8.4, which is already in unstable. see [1]. > please coordinate fixes with the security team. I have analy