Bug#760990: ntopng: Several vulnerabilities fixed upstream in 1.2.1

2014-09-10 Thread Luca Deri
Ludovico correct it is already fixed in 1.2.0 but in 1.2.1 we have improved the security checks Luca On 10 Sep 2014, at 02:14, Ludovico Cavedon wrote: > Hi Luca, > > my understanding (supported by a simple test and code check) was that > CVE-2014-4329 was fixed in version 1.2.0 > https://svn.

Bug#760990: ntopng: Several vulnerabilities fixed upstream in 1.2.1

2014-09-09 Thread Ludovico Cavedon
Hi Luca, my understanding (supported by a simple test and code check) was that CVE-2014-4329 was fixed in version 1.2.0 https://svn.ntop.org/bugzilla/show_bug.cgi?id=379 However, as Salvatore noticed, it is announced as being fixed in version 1.2.1. Can you confirm which version fixed it, please

Bug#760990: ntopng: Several vulnerabilities fixed upstream in 1.2.1

2014-09-09 Thread Salvatore Bonaccorso
Source: ntopng Severity: grave Tags: security upstream fixed-upstream Hi Ludovico, Marking this bugreport as grave, as more information seem a bit scarce, so was not able to identify the issues. There is an upstream report [1] which mentions several fixes were done in ntopng 1.2.1. [1] http://w