Bug#884881: apt-cacher-ng: Remap-... directives without TargetURLs are incompatible with ForceManaged

2017-12-20 Thread Alexander Cherepanov
y.debian.org I've put the 'security' tag on this bug as a straightforward and documented config will cause clients to miss security updates. A simple test from an admin of this setup would reveal the problem so the danger doesn't seem great:-) -- Alexander Cherepanov

Bug#775306: pxz: race condition in setting permissions on output file

2015-01-13 Thread Alexander Cherepanov
-bin/cvename.cgi?name=CVE-2013-0296 . -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#775218: ppmd: directory traversal vulnerability

2015-01-12 Thread Alexander Cherepanov
peed: 1 KB/sec $ ls ../rel ../rel -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774989: kgb: directory traversal vulnerability

2015-01-09 Thread Alexander Cherepanov
0KB -> 0KB w 0.00s. $ ls /tmp/abs /tmp/abs Notes: - kgb already rejects paths with .. ; - kgb doesn't handle symlinks at all. -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Troubl

Bug#774978: pigz: directory traversal vulnerability

2015-01-09 Thread Alexander Cherepanov
such file or directory $ unpigz -N rel.gz $ ls ../rel ../rel -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774954: ha: directory traversal vulnerabilities

2015-01-09 Thread Alexander Cherepanov
100.0 % $ ha x test.ha HA 0.999� Copyright (c) 1995 Harri Hirvola Archive : test.ha (2 files) Unpacking CPY 100 % /tmp/abs Unpacking CPY 100 % ../rel $ ls /tmp/abs ../rel ../rel /tmp/abs -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.o

Bug#774953: jar(1): directory traversal

2015-01-09 Thread Alexander Cherepanov
s just CVE-2005-1080 not fixed or something else. But please note that CVE-2005-1080 talks about .. only. -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774669: Directory traversal through symlinks

2015-01-07 Thread Alexander Cherepanov
_keys, i.e. your own files, strictly within filesystem permissions. Do you think this is a valid case for a CVE? Yes. -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774669: cpio: directory traversal vulnerability via symlinks

2015-01-07 Thread Alexander Cherepanov
rast with tar which is secure by default. -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774716: paxtar: directory traversal vulnerabilities

2015-01-06 Thread Alexander Cherepanov
For example, let's create a sample archive: ln -s /tmp dir paxtar cvf test.tar dir rm dir mkdir dir echo hello > dir/file paxtar rvf test.tar dir/file rm -r dir and then test it: paxtar xvf test.tar This will create a symlink "dir" in the current directory and

Bug#774669: Directory traversal through symlinks

2015-01-05 Thread Alexander Cherepanov
" in the current directory and a file "/tmp/file". -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774660: Directory traversal through symlinks

2015-01-05 Thread Alexander Cherepanov
e "/tmp/file". This can also be exploited through zip, arj and maybe other archives. -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#774211: freeze exception for binutils 2.25-3

2014-12-30 Thread Alexander Cherepanov
binutils/17512). Please note that PR binutils/17512 includes much more issues/fixes than those CVEs. And there is also PR binutils/17531 ... -- Alexander Cherepanov -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Conta

Bug#770166: Several crashes opening malformed files

2014-11-20 Thread Alexander Cherepanov
Hi, On 2014-11-19 15:11, Rene Engelhard wrote: On Wed, Nov 19, 2014 at 01:26:54PM +0300, Alexander Cherepanov wrote: Package: libreoffice Version: 1:3.5.4+dfsg2-0+deb7u2 Please note that there are several crashes in the version of LibreOffice shipped with Debian wheezy. Issues are reported

Bug#770166: Several crashes opening malformed files

2014-11-19 Thread Alexander Cherepanov
Package: libreoffice Version: 1:3.5.4+dfsg2-0+deb7u2 Please note that there are several crashes in the version of LibreOffice shipped with Debian wheezy. Issues are reported upstream, the list is here: http://www.openwall.com/lists/oss-security/2014/11/19/3 -- Alexander Cherepanov -- To