Bug#612034: vulnerability: rewrite arbitrary user file

2011-08-03 Thread Jonathan Wiltshire
Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: lenny (5.0.9) squeeze (6.0.3) Pleas

Bug#612034: vulnerability: rewrite arbitrary user file

2011-03-29 Thread Daniel Burrows
On Fri, Feb 04, 2011 at 04:53:54PM -0800, Kees Cook was heard to say: > Package: aptitude > Version: 0.6.3-3.2ubuntu1 > Severity: grave > Tags: security > Justification: user security hole > User: ubuntu-de...@lists.ubuntu.com > Usertags: origin-ubuntu natty > > This bug report was also filed in

Bug#612034: vulnerability: rewrite arbitrary user file

2011-03-29 Thread Daniel Burrows
The immediate problem should be fixed with 4a021fb5d4963d4e0756fcc182223b05939062d6. Unfortunately, I'm not sure that I can cut a security release before the weekend (it'll take some time and I'm still decobwebbing my dev box). Anyone who wants to cut a security NMU that cherry-picks the abov

Bug#612034: vulnerability: rewrite arbitrary user file

2011-02-04 Thread Kees Cook
Package: aptitude Version: 0.6.3-3.2ubuntu1 Severity: grave Tags: security Justification: user security hole User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu natty This bug report was also filed in Ubuntu and can be found at http://launchpad.net/bugs/607264 The description, from segooon