Bug#512191: websvn: WebSVN exposes protected files to users with insufficient permissions

2009-01-18 Thread Bas van Schaik
I've just downloaded the WebSVN 2.1 tarball and it is not vulnerable for this issue. Therefore, reporting to upstream doesn't make any sense... However, WebSVN 2.0 will appear in Lenny. I think the fix should be backported to 2.0 or Lenny should contain WebSVN 2.1. -- To UNSUBSCRIBE, email to

Bug#512191: websvn: WebSVN exposes protected files to users with insufficient permissions

2009-01-18 Thread Bas van Schaik
Florian Weimer wrote: > * Bas van Schaik: > >> When WebSVN is configured to use an SVN authz file to check user >> permissions, it only lists the repositories to which the user has >> been granted authorization (like expected). >> > Thanks. Has this be

Bug#512191: websvn: WebSVN exposes protected files to users with insufficient permissions

2009-01-18 Thread Bas van Schaik
Package: websvn Version: 2.0-4 Severity: grave Tags: security Justification: user security hole When WebSVN is configured to use an SVN authz file to check user permissions, it only lists the repositories to which the user has been granted authorization (like expected). However, a malicious (auth

Bug#500826: zabbix: Upgrade to Zabbix 1.6 does not work out-of-the-box, SQL upgrade scripts are not included in package?

2008-10-07 Thread Bas van Schaik
Michael Ablassmeier wrote: > hi Bas, > > On Tue, Oct 07, 2008 at 01:58:17PM +0200, Bas van Schaik wrote: > >> I didn't get any dbconfig-common question at all. Maybe it is important >> to note that my MySQL server is actually running on another server? >>

Bug#500826: zabbix: Upgrade to Zabbix 1.6 does not work out-of-the-box, SQL upgrade scripts are not included in package?

2008-10-07 Thread Bas van Schaik
Michael Ablassmeier wrote: > hi, > > On Wed, Oct 01, 2008 at 08:53:02PM +0200, Bas van Schaik wrote: > >> After upgrading my Zabbix 1.4.6 installation from Lenny to Zabbix 1.6 >> from Sid Zabbix does not work anymore, complaining about "unknown column >>

Bug#500826: zabbix: Upgrade to Zabbix 1.6 does not work out-of-the-box, SQL upgrade scripts are not included in package?

2008-10-01 Thread Bas van Schaik
Package: zabbix Version: 1.6 Severity: grave Justification: renders package unusable After upgrading my Zabbix 1.4.6 installation from Lenny to Zabbix 1.6 from Sid Zabbix does not work anymore, complaining about "unknown column 'g.gui_access'" and "unknown column 'g.users_status'". Clearly, upgrad

Bug#423822: pdns: Slave nameserver doesn't retry AXFR after a failure, new zones are missed

2007-05-14 Thread Bas van Schaik
Package: pdns Version: 2.9.20-8 Severity: grave Justification: causes non-serious data loss When a (super)master nameserver sends NOTIFY-packets to it's slave nameserver(s), those will queue an AXFR for the modified zone. However, if this AXFR fails (for example, because of a master nameserver get