Your message dated Mon, 12 Jan 2015 15:48:50 +0000
with message-id <e1yahey-0002ft...@franck.debian.org>
and subject line Bug#773085: fixed in xdg-utils 1.1.0~rc1+git20111210-7.3
has caused the Debian Bug report #773085,
regarding xdg-utils: command injection vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
773085: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773085
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
package: src:xdg-utils
severity: serious
version: 1.0.2+cvs20100307-2
control: tag -1 patch
control: forwarded -1 https://bugs.freedesktop.org/show_bug.cgi?id=66670
A command injection issue was disclosed for xdg-open:
http://seclists.org/fulldisclosure/2014/Nov/36
Patch for testing here:
https://bugs.freedesktop.org/attachment.cgi?id=109536
Best wishes,
Mike
--- End Message ---
--- Begin Message ---
Source: xdg-utils
Source-Version: 1.1.0~rc1+git20111210-7.3
We believe that the bug you reported is fixed in the latest version of
xdg-utils, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 773...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Vincent Bernat <ber...@debian.org> (supplier of updated xdg-utils package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sat, 10 Jan 2015 16:21:20 +0100
Source: xdg-utils
Binary: xdg-utils
Architecture: source all
Version: 1.1.0~rc1+git20111210-7.3
Distribution: unstable
Urgency: medium
Maintainer: Per Olofsson <pe...@debian.org>
Changed-By: Vincent Bernat <ber...@debian.org>
Description:
xdg-utils - desktop integration utilities from freedesktop.org
Closes: 773085
Changes:
xdg-utils (1.1.0~rc1+git20111210-7.3) unstable; urgency=medium
.
* Non-maintainer upload.
* Fix command injection vulnerability in xdg-open (closes: #773085).
Checksums-Sha1:
063cc6844ab83011f0dd214ce27918556a6099e0 2013
xdg-utils_1.1.0~rc1+git20111210-7.3.dsc
c689ecf7209d556b540d72145dc10fb6950262ea 10604
xdg-utils_1.1.0~rc1+git20111210-7.3.debian.tar.xz
0ab7cbb2bed5d198a2b1393cb138d81306ac3798 65018
xdg-utils_1.1.0~rc1+git20111210-7.3_all.deb
Checksums-Sha256:
f037b949018085593eafc086a8cd45e1e33f8e88a18c8455ba138345998a9bf3 2013
xdg-utils_1.1.0~rc1+git20111210-7.3.dsc
92730d55b500903663bd6302d46182bfbcce9f480d03b5e10d9e469803597015 10604
xdg-utils_1.1.0~rc1+git20111210-7.3.debian.tar.xz
6b26be9711da4c6a93b239f75832cc6d76dc6ca07cbd59d5b5dcb1cc76337575 65018
xdg-utils_1.1.0~rc1+git20111210-7.3_all.deb
Files:
508606c837d547e0bbff6aa41fdb7513 2013 utils optional
xdg-utils_1.1.0~rc1+git20111210-7.3.dsc
b12b55a8649e9c3b280e1d9f0c85be98 10604 utils optional
xdg-utils_1.1.0~rc1+git20111210-7.3.debian.tar.xz
7c6a5462ba43df99cf02485b9f84b8c5 65018 utils optional
xdg-utils_1.1.0~rc1+git20111210-7.3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJUsUT5AAoJEJWkL+g1NSX5NGgP/2VkEASee0xd7moySoeofbEj
hMt8kNvloZr/2WiXQ0kjyN6OMCRhCklo4unUrXZb9PkCcUR2GqVWJdJ0XWvPHt4M
oHGs2qJZqHJx1TfJ1kJhdCDH08EoXErmuK2clS83I/mN1QUJKhJ2+YvBuf8ofhlu
1ztxH1LbI04Ms/QhdyO0iOOctz1xs0y1VgGIJ4lyo49K1iqv0KpPPqt8fkT7c0k1
ipFU/n9zickAAFU6w8qGi7uGz2TligrNY1WMiR1Sh49PP+rgkTi/jB+WDBe1BWBR
Sil5relnLhJs0UemoRp/IAz63UrMQpJOmkbYKd8VXJ5l/N7uj/RjPU7hH3fV5GOi
wLVFF1oXAT3XH/YVyWDYpV9MWs2wrYTnBXCAKshUqeVQHiGjt3o60m90iUz3Lr3i
zagEoPkmStaydMsgedHG/sSbR7RQkhqVXS9drXZ945z0a53OuokCXCd7KjIMNQFL
Da8Y/D7sE/kGDre/2vmMqxCZAFWv2Vjn74tsgNvub+xmxb3aNTMuovyXdhsF+/4M
Lie/1zNvm+q80hzFB4Cfv/EPa7Q+hHvYLOAZ583aq4iIPrzXmG6xd5xF90LjdNq3
jA9o1rxk2VLFyT7MMN+z5STkG9SD9Etd/g31nJ7O7iPT2djLu7/FICv4G8WY+XJo
sCRM4BL/8bxmEzl6RO2a
=mnt3
-----END PGP SIGNATURE-----
--- End Message ---