Bug#573279: egroupware: 2 critial security bugs - remotely exploitable - without login
Package: egroupware Version: 1.6.002+dfsg-1~bpo50+1 Severity: critical Tags: security Justification: -1 1.6.003 has been published fixing 2 critical security bugs: http://www.egroupware.org/Home?category_id=95&item=93 In a debian-standard apache setup, "only" www-data user/group accesible files and commands are compromised. Update fixes a load of other non-security bugs and adds some new features too. Affected versions include all < 1.6.003 . -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 2.6.26-2-amd64 (SMP w/1 CPU core) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages egroupware depends on: ii egroupware-addres 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - addres ii egroupware-bookma 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - bookma ii egroupware-calend 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - calend ii egroupware-core 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - core m ii egroupware-develo 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - develo ii egroupware-emaila 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - e-mail ii egroupware-etempl 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - widget ii egroupware-felami 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - e-mail ii egroupware-filema 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - file m ii egroupware-infolo 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - infolo ii egroupware-manual 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - manual ii egroupware-news-a 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - news a ii egroupware-notifi 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - notifi ii egroupware-phpbra 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - phpbra ii egroupware-phpsys 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - phpSys ii egroupware-polls 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - pollin ii egroupware-projec 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - projec ii egroupware-regist 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - regist ii egroupware-resour 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - resour ii egroupware-sambaa 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - Samba ii egroupware-sitemg 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - site m ii egroupware-timesh 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - timesh ii egroupware-tracke 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - tracke ii egroupware-wiki 1.6.002+dfsg-1~bpo50+1 web-based groupware suite - wiki a egroupware recommends no packages. egroupware suggests no packages. -- no debconf information -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20100310093337.19891.69958.report...@intranet.binovo
Bug#573279: egroupware: 2 critial security bugs - remotely exploitable - without login
Looking closely at apache configuration file /etc/apache/conf.d/egroupware, seems that access is restricted to egroupware program and data files. -- Zuzendari Teknikoa / Director Técnico Binovo IT Human Project, S.L. Telf. 943493611 Astigarraga bidea 2, planta 2, Derecha, Oficina 6; 20180 Oiartzun www.binovo.es -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/1268217008.2022.4.ca...@elacunza-laptop
Bug#524683: marked as done (alltray: Alltray trayicons use their own tooltip theme)
Your message dated Wed, 10 Mar 2010 13:33:22 + with message-id and subject line Bug#524683: fixed in alltray 0.71a-1 has caused the Debian Bug report #524683, regarding alltray: Alltray trayicons use their own tooltip theme to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 524683: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=524683 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems --- Begin Message --- Package: alltray Version: 0.69-1 Severity: minor Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu jaunty ubuntu-patch Alltray should not use its own tooltip theme for the trayicon that it adds. It should respect the system theme. *** /tmp/tmpEJpcsm In Ubuntu, we've applied the attached patch to achieve the following: * Fix "alltray trayicons use their own tooltip theme" (LP: #355077) by adding 10-dont-use-pop-up-bubble.dpatch. We thought you might be interested in doing the same. -- System Information: Debian Release: lenny/sid APT prefers intrepid-updates APT policy: (500, 'intrepid-updates'), (500, 'intrepid-security'), (500, 'intrepid-backports'), (500, 'intrepid') Architecture: i386 (i686) Kernel: Linux 2.6.27-11-generic (SMP w/2 CPU cores) Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash diff -u alltray-0.69/debian/changelog alltray-0.69/debian/changelog diff -u alltray-0.69/debian/patches/00list alltray-0.69/debian/patches/00list --- alltray-0.69/debian/patches/00list +++ alltray-0.69/debian/patches/00list @@ -2,0 +3 @@ +10-dont-use-pop-up-bubble.dpatch only in patch2: unchanged: --- alltray-0.69.orig/debian/patches/10-dont-use-pop-up-bubble.dpatch +++ alltray-0.69/debian/patches/10-dont-use-pop-up-bubble.dpatch @@ -0,0 +1,61 @@ +#! /bin/sh /usr/share/dpatch/dpatch-run +## 10-dont-use-pop-up-bubble.dpatch by Kyran Lange +## +## All lines beginning with `## DP:' are a description of the patch. +## DP: Fix "alltray trayicons use their own tooltip theme" (LP: #355077) +## DP: src/trayicon.c and src/utils.c: Apply revision 25 from +## DP: old-maintenance branch upstream in order to stop alltray using its +## DP: own pop-up bubble for tooltips + +...@dpatch@ +diff -urNad alltray-0.69~/src/trayicon.c alltray-0.69/src/trayicon.c +--- alltray-0.69~/src/trayicon.c 2006-06-23 04:15:16.0 +0930 alltray-0.69/src/trayicon.c2009-04-16 12:39:06.0 +0930 +@@ -385,22 +385,6 @@ + + } + +-gboolean icon_window_enter_event(GtkWidget *widget, GdkEventButton * event, +-gpointer user_data) +-{ +- +- win_struct *win= (win_struct*) user_data; +- +- if (debug) printf ("icon window enter event\n"); +- +- win->balloon_message_allowed=TRUE; +- +- show_balloon (win, win->title, 0); +- +- return FALSE; +- +-} +- + void create_tray_and_dock (win_struct *win) + { + +@@ -479,12 +463,6 @@ + g_signal_connect ((gpointer) win->plug, "configure_event", + G_CALLBACK (icon_window_configure_event), + (gpointer) win); +- +- +- g_signal_connect ((gpointer) win->plug, "enter_notify_event", +-G_CALLBACK (icon_window_enter_event), +-(gpointer) win); +- + + dock_window (win->manager_window, win->plug_xlib); + +diff -urNad alltray-0.69~/src/utils.c alltray-0.69/src/utils.c +--- alltray-0.69~/src/utils.c 2009-04-16 12:39:06.0 +0930 alltray-0.69/src/utils.c 2009-04-16 12:39:06.0 +0930 +@@ -1517,7 +1517,7 @@ + win->title=g_strdup (title); + + if (debug) printf ("win->title: %s\n", win->title); +- ++gtk_widget_set_tooltip_text(win->plug, win->title); + g_free(title); + + if (win->title_time) --- End Message --- --- Begin Message --- Source: alltray Source-Version: 0.71a-1 We believe that the bug you reported is fixed in the latest version of alltray, which is due to be installed in the Debian FTP archive: alltray_0.71a-1.debian.tar.gz to main/a/alltray/alltray_0.71a-1.debian.tar.gz alltray_0.71a-1.dsc to main/a/alltray/alltray_0.71a-1.dsc alltray_0.71a-1_i386.deb to main/a/alltray/alltray_0.71a-1_i386.deb alltray_0.71a.orig.tar.gz to main/a/alltray/alltray_0.71a.orig.tar.gz A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 524...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Ignace Mouzannar (supplier of updated al
Bug#553650: marked as done ([alltray] FTBFS with binutils-gold)
Your message dated Wed, 10 Mar 2010 13:33:22 + with message-id and subject line Bug#553650: fixed in alltray 0.71a-1 has caused the Debian Bug report #553650, regarding [alltray] FTBFS with binutils-gold to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 553650: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=553650 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems --- Begin Message --- Package: alltray Version: 0.69-1 Severity: normal Tried to build your package and it fails to build with GNU binutils-gold. The important difference is that --no-add-needed is the default behavior of of GNU binutils-gold. Please provide all needed libraries to the linker when building your executables. x86_64-linux-gnu-gcc -Wall -Wall -g -O2 -o alltray main.o parent.o child.o utils.o trayicon.o balloon_message.o xmms.o clickmode.o binreloc.o grab.o gnome_theme.o kde.o clientwin.o shortcut.o eventfilter.o -L/usr/X11R6/lib /usr/lib/libgtk- x11-2.0.so /usr/lib/libatk-1.0.so /usr/lib/libpangoft2-1.0.so /usr/lib/libfreetype.so -lz -lfontconfig /usr/lib/libgdk- x11-2.0.so /usr/lib/libpangocairo-1.0.so /usr/lib/libgio-2.0.so /usr/lib/libpango-1.0.so /usr/lib/libcairo.so /usr/lib/libgconf-2.so /usr/lib/libgdk_pixbuf_xlib-2.0.so /usr/lib/libgdk_pixbuf-2.0.so -lm /usr/lib/libgobject-2.0.so /usr/lib/libgmodule-2.0.so /usr/lib/libglib-2.0.so -lpthread -Wl,--rpath -Wl,/usr/lib -Wl,--rpath -Wl,/usr/lib /usr/bin/ld: main.o: in function command_line_init:main.c:309: error: undefined reference to 'XParseGeometry' /usr/bin/ld: main.o: in function main:main.c:409: error: undefined reference to 'XGetWMHints' /usr/bin/ld: main.o: in function main:main.c:418: error: undefined reference to 'XSetWMHints' /usr/bin/ld: main.o: in function main:main.c:419: error: undefined reference to 'XFree' /usr/bin/ld: main.o: in function main:main.c:435: error: undefined reference to 'XCreateSimpleWindow' /usr/bin/ld: main.o: in function main:main.c:438: error: undefined reference to 'XAllocClassHint' /usr/bin/ld: main.o: in function main:main.c:441: error: undefined reference to 'XSetClassHint' /usr/bin/ld: main.o: in function main:main.c:442: error: undefined reference to 'XFree' /usr/bin/ld: main.o: in function main:main.c:444: error: undefined reference to 'XAllocWMHints' /usr/bin/ld: main.o: in function main:main.c:448: error: undefined reference to 'XSetWMHints' /usr/bin/ld: main.o: in function main:main.c:449: error: undefined reference to 'XFree' /usr/bin/ld: main.o: in function main:main.c:452: error: undefined reference to 'XGetWMNormalHints' /usr/bin/ld: main.o: in function main:main.c:468: error: undefined reference to 'XSetWMProtocols' /usr/bin/ld: main.o: in function main:main.c:470: error: undefined reference to 'XChangeProperty' /usr/bin/ld: main.o: in function main:main.c:474: error: undefined reference to 'XChangeProperty' /usr/bin/ld: main.o: in function main:main.c:480: error: undefined reference to 'XReparentWindow' /usr/bin/ld: main.o: in function main:main.c:481: error: undefined reference to 'XSync' /usr/bin/ld: main.o: in function main:main.c:483: error: undefined reference to 'XMapWindow' /usr/bin/ld: main.o: in function main:main.c:484: error: undefined reference to 'XSync' /usr/bin/ld: main.o: in function main:main.c:461: error: undefined reference to 'XSetWMNormalHints' /usr/bin/ld: parent.o: in function parse_arguments:parent.c:340: error: undefined reference to 'XParseGeometry' /usr/bin/ld: parent.o: in function parent_window_filter:parent.c:186: error: undefined reference to 'XSendEvent' /usr/bin/ld: parent.o: in function parent_window_filter:parent.c:174: error: undefined reference to 'XSetInputFocus' /usr/bin/ld: child.o: in function child_window_filter:child.c:616: error: undefined reference to 'XSelectInput' /usr/bin/ld: child.o: in function withdrawn:child.c:466: error: undefined reference to 'XGetWindowProperty' /usr/bin/ld: child.o: in function withdrawn:child.c:480: error: undefined reference to 'XFree' /usr/bin/ld: child.o: in function withdraw_window:child.c:531: error: undefined reference to 'XDefaultScreen' /usr/bin/ld: child.o: in function withdraw_window:child.c:531: error: undefined reference to 'XWithdrawWindow' /usr/bin/ld: child.o: in function withdraw_window:child.c:532: error: undefined reference to 'XSync' /usr/bin/ld: child.o: in function liballtraynomap_filter:child.c:240: error: undefined reference to 'XGetClassHint' /usr/bin/ld: child.o: in function exec_and_wait_for_window:child.c:381: error: undefined reference to 'XCreateSimpleWindow' /usr/bin/ld: child.o: in f
Bug#449598: marked as done (alltray: Please, provide a menu file)
Your message dated Wed, 10 Mar 2010 13:33:22 + with message-id and subject line Bug#449598: fixed in alltray 0.71a-1 has caused the Debian Bug report #449598, regarding alltray: Please, provide a menu file to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 449598: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=449598 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems --- Begin Message --- Package: alltray Version: 0.69-1 Severity: minor Hi! It would be nice to have a menu file for alltray Thank you! Best regards, Nelson -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: i386 (i686) Kernel: Linux 2.6.23-naoliv1 (SMP w/2 CPU cores; PREEMPT) Locale: LANG=pt_BR.UTF-8, LC_CTYPE=pt_BR.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages alltray depends on: ii libatk1.0-0 1.20.0-1 The ATK accessibility toolkit ii libc6 2.6.1-6 GNU C Library: Shared libraries ii libcairo2 1.4.10-1 The Cairo 2D vector graphics libra ii libfontconfig1 2.4.91-1 generic font configuration library ii libfreetype62.3.5-1+b1 FreeType 2 font engine, shared lib ii libgconf2-4 2.20.1-1 GNOME configuration database syste ii libglib2.0-02.14.2-1 The GLib library of C routines ii libgtk2.0-0 2.12.1-1 The GTK+ graphical user interface ii liborbit2 1:2.14.7-0.1 libraries for ORBit2 - a CORBA ORB ii libpango1.0-0 1.18.3-1 Layout and rendering of internatio ii libpng12-0 1.2.23~beta04-1 PNG library - runtime ii libx11-62:1.0.3-7X11 client-side library ii libxcursor1 1:1.1.9-1X cursor management library ii libxext61:1.0.3-2X11 miscellaneous extension librar ii libxfixes3 1:4.0.3-2X11 miscellaneous 'fixes' extensio ii libxi6 2:1.1.3-1X11 Input extension library ii libxinerama11:1.0.2-1X11 Xinerama extension library ii libxrandr2 2:1.2.2-1X11 RandR extension library ii libxrender1 1:0.9.4-1X Rendering Extension client libra ii zlib1g 1:1.2.3.3.dfsg-7 compression library - runtime alltray recommends no packages. -- no debconf information --- End Message --- --- Begin Message --- Source: alltray Source-Version: 0.71a-1 We believe that the bug you reported is fixed in the latest version of alltray, which is due to be installed in the Debian FTP archive: alltray_0.71a-1.debian.tar.gz to main/a/alltray/alltray_0.71a-1.debian.tar.gz alltray_0.71a-1.dsc to main/a/alltray/alltray_0.71a-1.dsc alltray_0.71a-1_i386.deb to main/a/alltray/alltray_0.71a-1_i386.deb alltray_0.71a.orig.tar.gz to main/a/alltray/alltray_0.71a.orig.tar.gz A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 449...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Ignace Mouzannar (supplier of updated alltray package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@debian.org) -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Sun, 07 Mar 2010 11:15:16 + Source: alltray Binary: alltray Architecture: source i386 Version: 0.71a-1 Distribution: unstable Urgency: low Maintainer: Ignace Mouzannar Changed-By: Ignace Mouzannar Description: alltray- Dock any program into the system tray Closes: 449598 524683 553650 566880 Changes: alltray (0.71a-1) unstable; urgency=low . * New upstream version: - Fixes Alltray trayicons use their owntooltip theme bug. (Closes: #524683) - Fixes FTBFS when building against binutils-gold. (Closes: #553650) * New maintainer. (Closes: #566880) * debian/control: - Bumped Standards-Version to 3.8.4. - Updated Maintainer field. - Added the Vcs-Browser address. - Added Build-Depends on bash-completion. * debian/rule: - Added "--with bash_completion" to include installation of the bash-completion file. * debian/copyright: - Updated copyright format, as it contained boilerplate from older
LED Moving Signs
Dear Sirs We got your name and address from Internet. I hope you everything is going on well. This is Aaron Liu, sales manager of Lycoin Electronic Limited. We would like to introduce Lycoin as a fantastic LED manufacturer to you. As a top leading company, Lycoin dedicate to LED manufacture for years. We are providing all kinds of custom/OEM/ODM services for LED Lighting and LED Display solutions. Go to our website, and send us your inquiry if any of our products finds your interest. There's nothing to lose, so why wait another minute? We are sure that you will have great benefits from this business opportunity. Our products include: 1. LED Bulb (E27, Gu10, MR16) 2 .LED Tube Lighting 3 .LED Strip Lighting 4 .LED Projection Lamp 5 .LED Car Display 6. LED Moving Signs 7. LED Table Signs 8. LED Gas/Oil Signs etc.. For more information, warmly welcome to our website www.lycoin.com. We thank you very much for your attention and looking forward to your reply soon. Your sincerely Aaron Liu Sales Manager Lycoin Electronic Limited Add: Room 28B, Block Xiangfen, Xiangbin Square, Bao'an District, Shenzhen, China http://www.lycoin.com Email: aa...@lycoin.com MSN: liuchunlin...@hotmail.com Tel: 0086-755-27780606 Mobile: 0086-13590402092 Fax: 0086-755-27780606 -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/00ff8e17$40247$0187983...@aaronliu
gnats 4.1.0-1 MIGRATED to testing
FYI: The status of the gnats source package in Debian's testing distribution has changed. Previous version: 4.1.0-0.7 Current version: 4.1.0-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See http://release.debian.org/testing-watch/ for more information. -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/e1npowm-0004eq...@ries.debian.org
php-idn 1.2b-6 MIGRATED to testing
FYI: The status of the php-idn source package in Debian's testing distribution has changed. Previous version: 1.2b-5.3 Current version: 1.2b-6 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See http://release.debian.org/testing-watch/ for more information. -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/e1npown-0004hj...@ries.debian.org
Guess, Diesel et Calvin Klei n à moitié prix avec TAA TOO
Si vous ne visualisez pas cet email : http://tre.emv3.com/HM?a=DNX7CkXrKHpH8SA9MOOXUX7nGHxKRn5Rsg8A CLUB AFFAIRES vous propose de profiter des offres de son partenaire TAA TOO TAA TOO, les marques à prix fou : de -30 à -80 pour cent sur de grandes marques Recevez 10€ de bon d'achats valable 1 AN en acceptant de recevoir nos offres promos et profitez ainsi de nos prix. - des T-shirts HOMME ET femme GUESS à partir de 19,90€ - des T-shirts HOMME ET femme CALVIN KLEIN à partir de 14,90€ - des Jeans HOMME ET femme DIESEL à partir de 39,90€ - des Jeans HOMME ET femme KAPORAL à partir de 39,90€ mais aussi d'autres marques : - Le temps des cerises - Dolce & Gabbana - Levi's - Kaporal 5 - Energie - Etc Utilisez le code : CLNH-10 http://tre.emv3.com/HU?a=DNX7CkXrKHpH8SA9MOOXUX7nGHxKRn5RRgDs Et encore plus de Service : Les frais de Port offert pour plus de 100€ d'achat, expédition sous 48H, un retour garantie et des conseillés à votre écoute? si vous ne souhaitez pas recevoir d'offre de notre partenaire TaaToo : http://tre.emv3.com/HD?a=DNX7CkXrKHpH8SA9MOOXUX7nGHxKRn5RQQDt * code valable 1 ans à partir du 12/11/2009
Já viu o que tem andado a perder?
- This mail is a HTML mail. Not all elements could be shown in plain text mode. - twingle Caso nao visualize correctamente este e-mail, por favor clique aqui Caso nao deseje voltar a receber campanhas publicitarias neste endereco de e-mail, por favor clique aqui