Bug#723034: Unsecure use of system()

2013-09-18 Thread Salvatore Bonaccorso
Control: retitle -1 davfs2: CVE-2013-4362: Unsecure use of system() Hi A CVE was assigned to this issue: CVE-2013-4362. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Processed: Re: Bug#723034: Unsecure use of system()

2013-09-18 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 davfs2: CVE-2013-4362: Unsecure use of system() Bug #723034 [davfs2] Unsecure use of system() Changed Bug title to 'davfs2: CVE-2013-4362: Unsecure use of system()' from 'Unsecure use of system()' -- 723034: http://bugs.debian.org/cgi-bin/bugreport.cgi?

Bug#723034: Unsecure use of system()

2013-09-15 Thread Werner Baumann
Package: davfs2 Version: 1.4.6-1.1 Severity: critical Tags: patch, security, upstream davfs2 calls function system several times. Because davfs2 is setuid root in many cases this will allow for privilege escalation. Appended are patches for version 1.4.6 and 1.4.7 that will fix this bug. Note: a