Bug#480972: vulnerable to symlink attacks

2008-05-21 Thread Sune Vuorela
On Thursday 22 May 2008, Nico Golde wrote: > Yes, same here. Looks like some deprecated package for kde > libs. I couldn't find that either in current source > packages. Marco, where did you get this information? Marco told me he got it from google code search. /Sune -- Man, do you know how cou

Bug#480972: vulnerable to symlink attacks

2008-05-21 Thread Nico Golde
Hi Sune, * Sune Vuorela <[EMAIL PROTECTED]> [2008-05-18 21:35]: > On Tuesday 13 May 2008, Marco d'Itri wrote: > > Security team: libuu-dev is a static-only library (see #216593). > > klibido, nget and slrn build-depend on libuu-dev, while > > libconvert-uulib-perl and kde (I don't know exactly whic

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Sune Vuorela
On Tuesday 13 May 2008, Marco d'Itri wrote: > Security team: libuu-dev is a static-only library (see #216593). > klibido, nget and slrn build-depend on libuu-dev, while > libconvert-uulib-perl and kde (I don't know exactly which package, > look in the kdesupport directory) contain an embedded copy

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Nico Golde
Hi Gregor, * gregor herrmann <[EMAIL PROTECTED]> [2008-05-18 15:40]: > On Tue, 13 May 2008 01:19:19 +0200, Marco d'Itri wrote: > > Security team: libuu-dev is a static-only library (see #216593). > > klibido, nget and slrn build-depend on libuu-dev, while > > libconvert-uulib-perl and kde (I don't

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread gregor herrmann
On Tue, 13 May 2008 01:19:19 +0200, Marco d'Itri wrote: > Security team: libuu-dev is a static-only library (see #216593). > klibido, nget and slrn build-depend on libuu-dev, while > libconvert-uulib-perl and kde (I don't know exactly which package, > look in the kdesupport directory) contain an e

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Marco d'Itri
Do you have any objections to me making a NMU to fix this bug AND to make the package generate a proper shared library? -- ciao, Marco signature.asc Description: Digital signature

Bug#480972: vulnerable to symlink attacks

2008-05-12 Thread Marco d'Itri
Package: libuu-dev Version: 0.5.20-3 Severity: critical Tags: security upstream Security team: libuu-dev is a static-only library (see #216593). klibido, nget and slrn build-depend on libuu-dev, while libconvert-uulib-perl and kde (I don't know exactly which package, look in the kdesupport directo