[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-08-10 Thread Launchpad Bug Tracker
This bug was fixed in the package fsniper - 1.3.1-0ubuntu2 --- fsniper (1.3.1-0ubuntu2) karmic; urgency=low * SECURITY UPDATE: Permissions of PID file are set on current umask rather than 600. (LP: #403116) - debian/patches/pid_file_permissons_to_600.patch: adjust src/

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-08-05 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/jaunty-security/fsniper -- Fsniper doesn't safely check file names. https://bugs.launchpad.net/bugs/403113 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-08-05 Thread Launchpad Bug Tracker
This bug was fixed in the package fsniper - 1.3.1-0ubuntu1.1 --- fsniper (1.3.1-0ubuntu1.1) jaunty-security; urgency=low * SECURITY UPDATE: Permissions of PID file are set on current umask rather than 600. (LP: #403116) - debian/patches/pid_file_permissons_to_600.patch: adju

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-08-05 Thread Marc Deslauriers
Thanks for the debdiff. The jaunty update is currently building. Please get a MOTU to sponsor the karmic upload to preserve the upgrade path. ** Changed in: fsniper (Ubuntu Jaunty) Status: In Progress => Fix Committed -- Fsniper doesn't safely check file names. https://bugs.launchpad.net

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-24 Thread Dave Walker
Attached is a further debdiff with modified changelog, and richer headers in the patches - as per PatchTaggingGuidelines. If this is suitable, and gets an "Ack" I will attach a suitable debdiff for Karmic. (or should it just be merged?). ** Attachment added: "fsniper_1.3.1-0ubuntu1.1.debdiff"

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-24 Thread Jamie Strandboge
For Jaunty it is preferred that you do not add a patch system since it introduces more changes to the package than are necessary. If you insist on adding the patch system, please follow https://wiki.ubuntu.com/UbuntuDevelopment/PatchTaggingGuidelines. As it is now, there is no attribution, originat

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-23 Thread Jamie Strandboge
Marking 'In Progress' per https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures ** Changed in: fsniper (Ubuntu Jaunty) Status: Triaged => In Progress -- Fsniper doesn't safely check file names. https://bugs.launchpad.net/bugs/403113 You received this bug notification because you are a mem

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-23 Thread Dave Walker
Thanks Kees. Jaunty debdiff attached with version -0ubuntu1.1 and packet jaunty- security. ** Attachment added: "fsniper_1.3.1-0ubuntu1.1.debdiff" http://launchpadlibrarian.net/29435243/fsniper_1.3.1-0ubuntu1.1.debdiff -- Fsniper doesn't safely check file names. https://bugs.launchpad.net/bu

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-23 Thread Kees Cook
Hi! Thanks for the debdiff. For Karmic, the MOTU sponsors should be able to handle this. For jaunty, we need to follow https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures Most notably, https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation mentions that the pocket must be jaunty-security, and

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-23 Thread Dave Walker
Oops! Thanks, replacement debdiff attached. ** Attachment added: "fsniper_1.3.1-0ubuntu2.debdiff" http://launchpadlibrarian.net/29432339/fsniper_1.3.1-0ubuntu2.debdiff -- Fsniper doesn't safely check file names. https://bugs.launchpad.net/bugs/403113 You received this bug notification because

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-23 Thread Brian Murray
Looking at your debdiff I noticed that you have: (Closes LP:#403116) However, the correct for closing the Launchpad bug includes a space so you'll really want: (Closes LP: #403116) Of course this is also true for the other bug in the changelog. Thanks! -- Fsniper doesn't safely check file na

[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-22 Thread Dave Walker
debdiff attached ** Attachment added: "fsniper_1.3.1-0ubuntu2.debdiff" http://launchpadlibrarian.net/29396961/fsniper_1.3.1-0ubuntu2.debdiff ** Changed in: fsniper (Ubuntu) Status: In Progress => Fix Committed ** Visibility changed to: Public -- Fsniper doesn't safely check file name