Bug#534918: patch

2009-06-28 Thread Giuseppe Iuculano
tags 534918 patch thanks Hi, Upstream patch: http://websvn.kde.org/?view=rev&revision=983306 Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

Bug#534947: CVE-2009-1709 CVE-2009-1698 CVE-2009-1690 CVE-2009-1687

2009-06-28 Thread Giuseppe Iuculano
Package: libqt4-webkit Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for qt4-x11. CVE-2009-1709[0]: | Use-after-free vulnerability in the garbage-collection implementation | in We

Bug#534949: CVE-2009-1698 CVE-2009-1690

2009-06-28 Thread Giuseppe Iuculano
Package: kde4libs Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for kde4libs. CVE-2009-1698[0]: | WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and | iPhone OS f

Bug#534951: CVE-2009-1709

2009-06-28 Thread Giuseppe Iuculano
Package: kdegraphics Version: 4:3.5.5-3etch3 4:3.5.9-3+lenny1 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kdegraphics. CVE-2009-1709[0]: | Use-after-free vulnerability in the

Bug#534952: CVE-2009-1698 CVE-2009-1690 CVE-2009-1687 CVE-2009-0945

2009-06-28 Thread Giuseppe Iuculano
Package: kdelibs Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for kdelibs. CVE-2009-1698[0]: | WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and | iPhone OS fo

Bug#534952: kdelibs is not affected by CVE-2009-0945

2009-06-28 Thread Giuseppe Iuculano
retitle 534952 CVE-2009-1698 CVE-2009-1690 CVE-2009-1687 thanks Apologies, kdelibs is not affected by CVE-2009-0945 Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

Bug#537931: CVE-2009-2537: denial of service via a large integer value for the length property of a Select object

2009-07-21 Thread Giuseppe Iuculano
Package: konqueror Severity: important Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for konqueror. CVE-2009-2537[0]: | KDE Konqueror allows remote attackers to cause a denial of service | (memory consumpt

Bug#545793: CVE-2009-2700: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName

2009-09-09 Thread Giuseppe Iuculano
Package: qt4-x11 Severity: grave Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for qt4-x11. CVE-2009-2700[0]: | src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not | properly handl

Bug#546212: CVE-2009-2702: KDE KSSL NULL Character Certificate Spoofing Vulnerability

2009-09-11 Thread Giuseppe Iuculano
Package: kdelibs,kde4libs Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kdelibs and kde4libs. CVE-2009-2702[0]: | KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a

kde4libs stable update for CVE-2009-2702

2009-10-13 Thread Giuseppe Iuculano
Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kde4libs some time ago. CVE-2009-2702[0]: | KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a | '\0' character in a domain name in the Subject Alternative Name field | of an X.509 certificate, which

Bug#534952: NMU

2009-10-14 Thread Giuseppe Iuculano
a legitimate Certification Authority (Closes: #546212) + + -- Giuseppe Iuculano Wed, 14 Oct 2009 09:57:26 +0200 + kdelibs (4:3.5.10.dfsg.1-2) unstable; urgency=low * Add 64_use_sys_inotify.diff patch to fix ftbfs caused by linux/inotify. only in patch2: unchanged: --- kdelibs-3.5.10.

Bug#553209: Fwd: [SECURITY] [DSA 1916-1] New kdelibs packages fix SSL certificate verification weakness

2009-10-30 Thread Giuseppe Iuculano
Hi, Helge Kreutzmann ha scritto: > clone 546212 -1 > found -1 4:3.5.10.dfsg.1-0lenny2 > severity -1 serious > thanks > > - Forwarded message from Giuseppe Iuculano - > ... >> Debian Security Advisory DSA-1916-1 secur...@debian.org >&g

Bug#559265: CVE-2009-0689: remote array overrun

2009-12-03 Thread Giuseppe Iuculano
Package: kdelibs Severity: grave Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kdelibs. CVE-2009-0689[0]: | The gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc in | FreeBSD 6.4 and 7.

Bug#559266: CVE-2009-0689: remote array overrun

2009-12-03 Thread Giuseppe Iuculano
Package: kde4libs Severity: grave Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kde4libs. CVE-2009-0689[0]: | The gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc in | FreeBSD 6.4 and

kde4libs update for CVE-2009-0689 in stable

2010-03-29 Thread Giuseppe Iuculano
Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kde4libs some time ago. CVE-2009-0689[0]: | Array index error in the (1) dtoa implementation in dtoa.c (aka | pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in | gdtoa/misc.c in libc, as used in multiple oper