[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-26 Thread Kees Cook
Published now... gsambad | 0.1.4-2ubuntu0.1 | feisty-security/universe gsambad | 0.1.3-2ubuntu0.1 | edgy-security/universe ** Changed in: gsambad (Ubuntu Edgy) Status: Fix Committed => Fix Released ** Changed in: gsambad (Ubuntu Feisty) Status: Fix Committed => Fix Released -- [

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-17 Thread Michael Bienia
gsambad (0.1.6-2ubuntu1) gutsy; urgency=low * debian/patches/04-cve-2007-2838.dpatch: This is an improved version of the debian patch, use it instead of 04-tempfile.dpatch (LP: #124629) * debian/control: Modify Maintainer value to match DebianMaintainerField spec. -- Michael Bien

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-17 Thread Michael Bienia
Filed in Debian as http://bugs.debian.org/cgi- bin/bugreport.cgi?bug=433518 And I also uploaded the fix to gutsy (I only waited on your review of the improved patch). -- [CVE-2007-2838] Unsafe tmp file usage https://bugs.launchpad.net/bugs/124629 You received this bug notification because you ar

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-17 Thread Kees Cook
Looks great! Thanks very much. Could you also open a Debian bug report about the "incomplete" fix? I'd like to see it fixed right in gutsy (hopefully with a sync from Debian). edgy/feisty are building currently, and I'll get them published shortly. ** Changed in: gsambad (Ubuntu Feisty)

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-10 Thread Michael Bienia
Updated debdiff for edgy. ** Attachment added: "Update debdiff for edgy-security." http://launchpadlibrarian.net/8358862/edgy.debdiff -- [CVE-2007-2838] Unsafe tmp file usage https://bugs.launchpad.net/bugs/124629 You received this bug notification because you are a member of Ubuntu Bugs, whi

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-10 Thread Michael Bienia
Updated debdiff for feisty. ** Changed in: gsambad (Ubuntu) Assignee: (unassigned) => Michael Bienia Status: Fix Released => In Progress ** Attachment added: "Update debdiff for feisty-security." http://launchpadlibrarian.net/8357940/feisty.debdiff -- [CVE-2007-2838] Unsafe tmp f

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-09 Thread Kees Cook
Thanks for getting these prepared! Two observations: - the packaging uses "dpatch", so the patch needs to be re-worked to create a patch in debian/patches and update the 00list file. - the fix isn't a full fix. I would have expected either the use of "mkstemp" or at least "umask" for the file c

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-08 Thread Michael Bienia
Here is a debdiff for edgy-security. gsambad was first shipped with edgy. ** Attachment added: "debdiff for edgy-security" http://launchpadlibrarian.net/8335624/edgy.debdiff ** Changed in: gsambad (Ubuntu Edgy) Status: New => Confirmed -- [CVE-2007-2838] Unsafe tmp file usage https:/

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-08 Thread William Grant
Does this affect releases prior to Feisty? ** Changed in: gsambad (Ubuntu) Status: Confirmed => Fix Released ** Changed in: gsambad (Ubuntu Feisty) Status: New => Confirmed -- [CVE-2007-2838] Unsafe tmp file usage https://bugs.launchpad.net/bugs/124629 You received this bug notifi

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-07 Thread Jim Qode
** Changed in: gsambad (Ubuntu) Status: New => Confirmed -- [CVE-2007-2838] Unsafe tmp file usage https://bugs.launchpad.net/bugs/124629 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bug

[Bug 124629] Re: [CVE-2007-2838] Unsafe tmp file usage

2007-07-07 Thread Michael Bienia
** Attachment added: "debdiff for feisty-security" http://launchpadlibrarian.net/8334163/feisty.debdiff ** Visibility changed to: Public ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-2838 ** Description changed: Binary package hint: gsambad - Here is a debdiff f