Bug#652663: CVE-2011-4612

2012-09-16 Thread Rücker Thomas
On 06/09/12 19:05, Moritz Muehlenhoff wrote: On Tue, Jun 26, 2012 at 06:36:56PM +0300, Rücker Thomas wrote: Hi Jonas, On 13/06/12 02:02, Jonas Smedegaard wrote: Hi Thomas, On 12-06-13 at 12:50am, Rücker Thomas wrote: Hello, your friendly upstream here. We just released Icecast 2.3.3 which

Bug#652663: CVE-2011-4612

2012-06-26 Thread Rücker Thomas
Hi Jonas, On 13/06/12 02:02, Jonas Smedegaard wrote: Hi Thomas, On 12-06-13 at 12:50am, Rücker Thomas wrote: Hello, your friendly upstream here. We just released Icecast 2.3.3 which addresses this issue. Also for the record. It's fairly easy to spot those injection attempts by looki

Bug#652663: CVE-2011-4612

2012-06-12 Thread Rücker Thomas
Hello, your friendly upstream here. We just released Icecast 2.3.3 which addresses this issue. Also for the record. It's fairly easy to spot those injection attempts by looking at the Icecast access log. Cheers Thomas -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org w

Bug#341876: Fixed in upstream

2012-06-12 Thread Rücker Thomas
Hi, your friendly upstream here! This should be fixed in the Icecast 2.3.3 release that we just published. We only accept metadata updates from the same IP as the source client. Of course if the two source clients are coming from the same IP... But then the chance that you can go over and smack