Bug#731848: CVE request for remote code execution in ack

2013-12-10 Thread Andy Lester
On Dec 10, 2013, at 7:46 AM, Axel Beckert wrote: > Hi, > > as discussed with Salvatore Bonaccorso of the Debian Security Team > (team cc'ed), I'm herewith requesting a CVE ID for the following > security issue in ack (http://beyondgrep.com/, also known as ack-grep > in multiple distributions; u

Bug#731848: CVE request for remote code execution in ack

2013-12-10 Thread Andy Lester
On Dec 10, 2013, at 8:00 AM, Axel Beckert wrote: > It would be nice if you could add the CVE-ID to the Changes file of > ack retroactively as soon as it's known so that it's part of the > Changes file in further ack releases. OK. Just help me through this and I’ll do what needs to be done. I

Bug#731848: CVE request for remote code execution in ack

2013-12-10 Thread Axel Beckert
Hi Andy, Andy Lester wrote: > On Dec 10, 2013, at 7:46 AM, Axel Beckert wrote: > > as discussed with Salvatore Bonaccorso of the Debian Security Team > > (team cc'ed), I'm herewith requesting a CVE ID for the following > > security issue in ack (http://beyondgrep.com/, also known as ack-grep > >

Bug#731848: CVE request for remote code execution in ack

2013-12-10 Thread Axel Beckert
Hi, as discussed with Salvatore Bonaccorso of the Debian Security Team (team cc'ed), I'm herewith requesting a CVE ID for the following security issue in ack (http://beyondgrep.com/, also known as ack-grep in multiple distributions; upstream developer cc'ed): * Remote code execution via options -