Bug#561762: kde4libs: many webkit vulnerabilities

2010-09-05 Thread Moritz Muehlenhoff
On Wed, Apr 28, 2010 at 09:46:44PM +0200, Moritz Muehlenhoff wrote: > On Sun, Apr 25, 2010 at 11:05:09PM +0200, Eckhart Wörner wrote: > > Hi Moritz, > > > > > Since you're writing with a @kde.org address: My mail to secur...@kde.org > > > was left unanswered. Do you have a suggestion who to contac

Bug#561762: kde4libs: many webkit vulnerabilities

2010-04-28 Thread Moritz Muehlenhoff
On Sun, Apr 25, 2010 at 11:05:09PM +0200, Eckhart Wörner wrote: > Hi Moritz, > > > Since you're writing with a @kde.org address: My mail to secur...@kde.org > > was left unanswered. Do you have a suggestion who to contact instead? > > secur...@kde.org is the right place and several people have pr

Bug#561762: kde4libs: many webkit vulnerabilities

2010-04-25 Thread Eckhart Wörner
Hi Moritz, > Since you're writing with a @kde.org address: My mail to secur...@kde.org > was left unanswered. Do you have a suggestion who to contact instead? secur...@kde.org is the right place and several people have probably read your mail, however, there has been some problem in March with a

Bug#561762: kde4libs: many webkit vulnerabilities

2010-04-25 Thread Moritz Muehlenhoff
Hi Eckhart, On Sun, Apr 04, 2010 at 02:34:32AM +0200, Eckhart Wörner wrote: > > > CVE-2009-1703[25]: > > > | WebKit in Apple Safari before 4.0 does not prevent references to file: > > > | URLs within (1) audio and (2) video elements, which allows remote > > > | attackers to determine the existence

Bug#561762: kde4libs: many webkit vulnerabilities

2010-04-03 Thread Eckhart Wörner
> > CVE-2009-1703[25]: > > | WebKit in Apple Safari before 4.0 does not prevent references to file: > > | URLs within (1) audio and (2) video elements, which allows remote > > | attackers to determine the existence of arbitrary files via a crafted > > | HTML document. > > This doesn't affect kde4l

Bug#561762: kde4libs: many webkit vulnerabilities

2010-04-03 Thread Moritz Muehlenhoff
Michael Gilbert wrote: > Package: kde4libs > Version: 4:4.3.4-1 > Severity: serious > Tags: security > > Hi, > > The following CVE (Common Vulnerabilities & Exposures) ids were > published for webkit. webkit was forked from khtml, so these > issues very like apply to this package as well. Since

Bug#561762: kde4libs: many webkit vulnerabilities

2010-03-12 Thread Eckhart Wörner
block 561762 by 537931 thanks The bug report mentions CVE-2009-1692 which has its konqueror/khtml counterpart at CVE-2009-2537, tracked at http://bugs.debian.org/cgi- bin/bugreport.cgi?bug=537931 -- To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org with a subject of "unsubscribe

Bug#561762: kde4libs: many webkit vulnerabilities

2009-12-19 Thread Michael Gilbert
Package: kde4libs Version: 4:4.3.4-1 Severity: serious Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for webkit. webkit was forked from khtml, so these issues very like apply to this package as well. Since there are so many problems, I have not had