Bug#751910: Bug:#751910: zabbix: CVE-2014-3005: local file inclusion via XXE

2014-07-05 Thread Dmitry Smirnov
On Thu, 3 Jul 2014 10:11:15 Alexei Vladishev wrote: > Since 2.2.5 fixes this security related issue we'll do all our best to > release it asap. > > I hope first RC will be ready early next week. Thanks for ETA. Once 2.2.5 is released I'll do my best to upload it to Debian ASAP. -- All the best

Bug#751910: Bug:#751910: zabbix: CVE-2014-3005: local file inclusion via XXE

2014-07-03 Thread Alexei Vladishev
Hi Dmitry, The issues has already been fixed and will be available in Zabbix 2.2.5 soon. Thank you for quick action. Do you want us to prepare a patch for 2.2.3? Thank you for your help with patching of current versions of Zabbix in Debian -- much appreciated. I'm working on 2.2.4 so perhaps

Bug#751910: Bug:#751910: zabbix: CVE-2014-3005: local file inclusion via XXE

2014-07-02 Thread Dmitry Smirnov
Hi Alexei, On Wed, 2 Jul 2014 14:15:49 Alexei Vladishev wrote: > The issues has already been fixed and will be available in Zabbix 2.2.5 > soon. Thank you for quick action. > Do you want us to prepare a patch for 2.2.3? Thank you for your help with patching of current versions of Zabbix in Debi

Bug#751910: zabbix: CVE-2014-3005: local file inclusion via XXE

2014-06-17 Thread Henri Salo
Package: zabbix Version: 1:2.2.3+dfsg-1 Severity: grave Tags: security Advisory: http://seclists.org/fulldisclosure/2014/Jun/87 Below might be the fix, but please verify. --- Henri Salo svn diff -r46596:46600 Index: frontends/php/include/defines.inc.php =