Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-24 Thread Damyan Ivanov
-=| Moritz Muehlenhoff, 14.10.2011 17:54:44 +0200 |=- > On Wed, Oct 12, 2011 at 12:03:50PM +0300, Damyan Ivanov wrote: > > > > Hello Damyan, are you planning to do this or do you need someone > > > else to take over? IMO this one warrants a DSA. > > > > Thanks for the nudge. I have pushed the sq

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-20 Thread Moritz Mühlenhoff
On Fri, Oct 14, 2011 at 05:54:44PM +0200, Moritz Muehlenhoff wrote: > On Wed, Oct 12, 2011 at 12:03:50PM +0300, Damyan Ivanov wrote: > > > > Hello Damyan, are you planning to do this or do you need someone > > > else to take over? IMO this one warrants a DSA. > > > > Thanks for the nudge. I have

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-14 Thread Moritz Muehlenhoff
On Wed, Oct 12, 2011 at 12:03:50PM +0300, Damyan Ivanov wrote: > > Hello Damyan, are you planning to do this or do you need someone > > else to take over? IMO this one warrants a DSA. > > Thanks for the nudge. I have pushed the squeeze branch of > http://anonscm.debian.org/gitweb/?p=pkg-perl/pa

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-12 Thread Russ Allbery
Dominic Hargreaves writes: > On Wed, Oct 12, 2011 at 12:03:50PM +0300, Damyan Ivanov wrote: >> The changes look sane "in theory". They address all mentions of >> FCGI::ENV in the source. >> The RT testing by Dominic seems sufficient additional assurance to me. > Russ, I guess you've been invol

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-12 Thread Dominic Hargreaves
On Wed, Oct 12, 2011 at 12:03:50PM +0300, Damyan Ivanov wrote: > -=| Dominic Hargreaves, 11.10.2011 14:33:42 +0100 |=- > > On Sat, Oct 01, 2011 at 12:44:33PM +0200, Moritz Mühlenhoff wrote: > > > Did update this receive testing? > > The changes look sane "in theory". They address all mentions of

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-12 Thread Damyan Ivanov
-=| Dominic Hargreaves, 11.10.2011 14:33:42 +0100 |=- > On Sat, Oct 01, 2011 at 12:44:33PM +0200, Moritz Mühlenhoff wrote: > > Did update this receive testing? The changes look sane "in theory". They address all mentions of FCGI::ENV in the source. The RT testing by Dominic seems sufficient addi

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-11 Thread Dominic Hargreaves
On Sat, Oct 01, 2011 at 12:44:33PM +0200, Moritz Mühlenhoff wrote: > On Sat, Oct 01, 2011 at 08:12:18AM +0300, Damyan Ivanov wrote: > > -=| Dominic Hargreaves, 30.09.2011 18:26:41 +0100 |=- > > > I'm reopening the bug, because I believe this fix applies to > > > squeeze, and should be fixed there.

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-05 Thread Dominic Hargreaves
On Sat, Oct 01, 2011 at 12:44:33PM +0200, Moritz Mühlenhoff wrote: > On Sat, Oct 01, 2011 at 08:12:18AM +0300, Damyan Ivanov wrote: > > Porting the patch (for some reason it doesn't apply cleanly) is > > trivial. Attached is a patch that does exactly that (to be git > > apply'ed to the debian/0.

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-05 Thread Dominic Hargreaves
On Sat, Oct 01, 2011 at 08:12:18AM +0300, Damyan Ivanov wrote: > -=| Dominic Hargreaves, 30.09.2011 18:26:41 +0100 |=- > > I'm reopening the bug, because I believe this fix applies to > > squeeze, and should be fixed there. > > Agreed. > > > Has anyone yet contacted the security team about this/

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-10-01 Thread Moritz Mühlenhoff
On Sat, Oct 01, 2011 at 08:12:18AM +0300, Damyan Ivanov wrote: > -=| Dominic Hargreaves, 30.09.2011 18:26:41 +0100 |=- > > I'm reopening the bug, because I believe this fix applies to > > squeeze, and should be fixed there. > > Agreed. > > > Has anyone yet contacted the security team about this/

Bug#607479: libfcgi-perl/CVE-2011-2766 authentication bypass

2011-09-30 Thread Damyan Ivanov
-=| Dominic Hargreaves, 30.09.2011 18:26:41 +0100 |=- > I'm reopening the bug, because I believe this fix applies to > squeeze, and should be fixed there. Agreed. > Has anyone yet contacted the security team about this/is anyone > working on packages for squeeze? I don't think so. Porting the