Re: [Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-22 Thread Axel Braun
Am Samstag, 20. Juni 2020, 16:53:31 CEST schrieb Luis Falcon: > PS. @Axel: The file that you have uploaded only changes http by https. I > think you uploaded the wrong file. Indeed, my bad. I had send you the correctly patched file already on 24 March. But good that it is fixed now! Cheers Axel

[Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-20 Thread Luis Falcon
Update of bug #58584 (project health): Severity: 4 - Important => 3 - Normal Status:None => Fixed Assigned to:None => meanmicio Open/Closed:

Re: [Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-20 Thread Luis Falcon
Dear all I have submitted some patches for GNU Health control, including some recommendations from openSUSE security assessment. Some notes that you might want to consider for the openSUSE version of the GH control center: * Keep in mind that the standard GNU Health installation uses a non-p

Re: [Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-17 Thread Luis Falcon
Dear Axel On Wed, 17 Jun 2020 13:47:13 +0200 Axel Braun wrote: > Hello Luis, > > I have already informed you three month ago in a private, encrypted > mail about this issue - solution was provided on 23 March, as well in > an encrypted mail. > I know you have acted in good faith, and I apprec

Re: [Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-17 Thread Axel Braun
Hello Luis, I have already informed you three month ago in a private, encrypted mail about this issue - solution was provided on 23 March, as well in an encrypted mail. Release 3.6.4 was one month ago, and I had emphasized this to you as well. Too bad that it was ignored, as I just found out. B

Re: [Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-17 Thread Luis Falcon
Hi Axel, Johannes Axel, please before sending any potential vulnerability, practice coordinated disclosure. Make sure you write to "secur...@gnuhealth.org"[1] so we can discuss and apply the pertinent patches if needed. This particular context is not critical, but if it would be the case, you wou

[Health-dev] [bug #58584] Various security issues for gnuhealth-control

2020-06-16 Thread Axel Braun
URL: Summary: Various security issues for gnuhealth-control Project: GNU Health Submitted by: coogor Submitted on: Tue 16 Jun 2020 05:42:54 PM UTC Category: Security S