Re: tkman stable update for CVE-2008-5137

2008-12-15 Thread Maximiliano Curia
Hola Philipp Kern! El 15/12/2008 a las 17:38 escribiste: > It's not acceptable due to it based on the unstable version instead of the > stable one. Please provide a targetted fix for stable. Rejecting. Thanks for reviewing it, I've applied the patch to the 2.2-2 version, and reuploaded as 2.2-2

Re: tkman stable update for CVE-2008-5137

2008-12-15 Thread Philipp Kern
On Sun, Dec 14, 2008 at 11:07:10PM -0200, Maximiliano Curia wrote: > El 12/12/2008 a las 20:49 escribiste: > > > I've just uploaded a patched version (2.2-4), I'll be happy if someone > > > reviews > > > the patch. > > Oh, I see that upload was to unstable, which is great for Lenny, but I > > thin

Re: tkman stable update for CVE-2008-5137

2008-12-14 Thread Maximiliano Curia
Hola Adeodato Simó! El 12/12/2008 a las 20:49 escribiste: > > I've just uploaded a patched version (2.2-4), I'll be happy if someone > > reviews > > the patch. > Oh, I see that upload was to unstable, which is great for Lenny, but I > think Nico meant an upload to stable-proposed-updates. Do th

Re: tkman stable update for CVE-2008-5137

2008-12-12 Thread Adeodato Simó
* Maximiliano Curia [Sun, 30 Nov 2008 12:08:13 -0200]: > Hola Nico Golde! Hola Maxi! > El 30/11/2008 a las 10:44 escribiste: > > Hi, > > the following CVE (Common Vulnerabilities & Exposures) id was > > published for tkman some time ago. > > CVE-2008-5137[0]: > > | tkman in tkman 2.2 allows loc

Re: tkman stable update for CVE-2008-5137

2008-11-30 Thread Maximiliano Curia
Hola Nico Golde! El 30/11/2008 a las 10:44 escribiste: > Hi, > the following CVE (Common Vulnerabilities & Exposures) id was > published for tkman some time ago. > CVE-2008-5137[0]: > | tkman in tkman 2.2 allows local users to overwrite arbitrary files via > | a symlink attack on a (1) /tmp/tkman