[Bug 261962] Re: tmpfile vunerability

2010-03-29 Thread Jamie Strandboge
twiki (1:4.1.2-3.2ubuntu1.1) intrepid-security; urgency=low * Changes taken from Debian version 4.1.2-4 * SECURITY UPDATE: Possible symlink attack through /tmp directory - move session files to /var/lib/twiki/working/tmp - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494648 * deb

[Bug 261962] Re: tmpfile vunerability

2010-03-26 Thread Jamie Strandboge
Uploaded to security queue. ** Changed in: twiki (Ubuntu Intrepid) Status: Confirmed => Fix Committed -- tmpfile vunerability https://bugs.launchpad.net/bugs/261962 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs

[Bug 261962] Re: tmpfile vunerability

2010-03-26 Thread Jamie Strandboge
Sorry the security patch got neglected for so long. It didn't pop up on our reports due to how it was filed. ACK (the patch is slightly different from what landed in Jaunty, but is nearly the same). ** Changed in: twiki (Ubuntu Intrepid) Status: New => Confirmed -- tmpfile vunerability h

[Bug 261962] Re: tmpfile vunerability

2010-03-26 Thread Jamie Strandboge
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-4998 -- tmpfile vunerability https://bugs.launchpad.net/bugs/261962 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubun

[Bug 261962] Re: tmpfile vunerability

2010-03-20 Thread Artur Rona
I'm subscribing ubuntu-security-sponsors for intrepid's debdiff review. -- tmpfile vunerability https://bugs.launchpad.net/bugs/261962 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.