Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Jeroen van Wolffelaar
On Tue, May 30, 2006 at 06:21:39PM +0100, Steve Kemp wrote: > On Tue, May 30, 2006 at 07:14:11PM +0200, Jeroen van Wolffelaar wrote: > > On Tue, May 30, 2006 at 09:55:16AM +0200, Thijs Kinkhorst wrote: > > > On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: > > > > Uploaded. > > > > > > Thank

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Steve Kemp
On Tue, May 30, 2006 at 07:14:11PM +0200, Jeroen van Wolffelaar wrote: > On Tue, May 30, 2006 at 09:55:16AM +0200, Thijs Kinkhorst wrote: > > On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: > > > Uploaded. > > > > Thanks! But... can't find the upload anywhere? Maybe something went > > wrong

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Jeroen van Wolffelaar
On Tue, May 30, 2006 at 09:55:16AM +0200, Thijs Kinkhorst wrote: > On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: > > Uploaded. > > Thanks! But... can't find the upload anywhere? Maybe something went > wrong or am I looking the wrong way? I got a 'upload removed due to not being signed by

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Thijs Kinkhorst
On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: > Uploaded. Thanks! But... can't find the upload anywhere? Maybe something went wrong or am I looking the wrong way? Thijs -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-28 Thread Steve Kemp
On Sun, May 28, 2006 at 11:02:18PM +0200, Thijs Kinkhorst wrote: > On Tue, 2006-05-23 at 12:36 +0200, Thijs Kinkhorst wrote: > > Problem is that Jeroen announced that he's on a trip through Mexico > > now, > > so I'm left without someone to upload. Maybe the (testing) security > > team > > or any o

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-28 Thread Thijs Kinkhorst
On Tue, 2006-05-23 at 12:36 +0200, Thijs Kinkhorst wrote: > Problem is that Jeroen announced that he's on a trip through Mexico > now, > so I'm left without someone to upload. Maybe the (testing) security > team > or any other DD interested in getting this bug fixed, can take a look > and upload? >

Processed: Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 365533 pending Bug#365533: CVE-2006-1896: Admin command execution Tags were: patch security Tags added: pending > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (adminis

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-23 Thread Thijs Kinkhorst
tags 365533 pending thanks On Thu, 2006-05-18 at 05:21 +0200, Moritz Muehlenhoff wrote: > > W.r.t. unstable, I will look into that very soon, we'll need to be > > upgrading to a new upstream aswell. I'll check whether that can be done > > in the short term, if not, I'll prepare a patched package.

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-17 Thread Moritz Muehlenhoff
Thijs Kinkhorst wrote: > On Mon, 2006-05-15 at 08:31 +0200, Jeroen van Wolffelaar wrote: > > On Wed, May 03, 2006 at 10:56:33AM +0200, Thijs Kinkhorst wrote: > > > Thanks for the report. While I think that people who are admin can > > > already do a lot of damage and should hence be considered trus

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-17 Thread Thijs Kinkhorst
On Mon, 2006-05-15 at 08:31 +0200, Jeroen van Wolffelaar wrote: > On Wed, May 03, 2006 at 10:56:33AM +0200, Thijs Kinkhorst wrote: > > Thanks for the report. While I think that people who are admin can > > already do a lot of damage and should hence be considered trusted, > > executing php code is

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-14 Thread Jeroen van Wolffelaar
tags 365533 patch thanks On Wed, May 03, 2006 at 10:56:33AM +0200, Thijs Kinkhorst wrote: > Thanks for the report. While I think that people who are admin can > already do a lot of damage and should hence be considered trusted, > executing php code is a step further in permissions and thus this ca

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-03 Thread Thijs Kinkhorst
On Sun, 2006-04-30 at 21:31 +0200, Stefan Fritsch wrote: > Unspecified vulnerability in phpBB allows remote authenticated users > with Administration Panel access to execute arbitrary PHP code via > crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature > values, possibly involving th

Bug#365533: CVE-2006-1896: Admin command execution

2006-04-30 Thread Stefan Fritsch
Package: phpbb2 Severity: grave Tags: security Justification: user security hole CVE-2006-1896: Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signatu