[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread Kees Cook
** Changed in: lighttpd (Ubuntu Edgy) Status: Fix Committed => Fix Released -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubunt

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread Kees Cook
** Changed in: lighttpd (Ubuntu Feisty) Status: Fix Committed => Fix Released ** Changed in: lighttpd (Ubuntu Dapper) Status: Fix Committed => Fix Released ** Changed in: lighttpd (Ubuntu Edgy) Status: In Progress => Fix Committed -- lighttpd security fixes https://bugs.lau

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread Leonel Nunez
aplied this patch http://launchpadlibrarian.net/8743252/lighttpd_1.4.13%7Er1370-1ubuntu1.2.debdiff builded and tested in Edgy No problems found -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread Kees Cook
Fixed in gutsy, publications for dapper/feisty are on their way now. :) ** Changed in: lighttpd (Ubuntu Feisty) Status: In Progress => Fix Committed ** Changed in: lighttpd (Ubuntu Dapper) Status: In Progress => Fix Committed ** Changed in: lighttpd (Ubuntu) Status: In Prog

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread asommer
Tested the dapper patch and it builds and serves pages fine. I followed the same procedure for dapper as I did for feisty above. The mod_access bug went away with the update. -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a m

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread asommer
I can also confirm this mod_access bug: http://www.lighttpd.net/assets/2007/7/24/lighttpd_sa2007_08.txt bug is present in lighttpd-1.4.13-9ubuntu4 and fixed in lighttpd-1.4.13-9ubuntu4.1 (version created after applying debdiff). To test I edited this line in /etc/lighttpd/lighttpd.conf: url.a

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread asommer
I tested the fiesty patch: https://bugs.launchpad.net/ubuntu/+source/lighttpd/+bug/127718/comments/4 Everything built and worked fine for me. lighttpd served pages fine and didn't have any errors. -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notificat

[Bug 127718] Re: lighttpd security fixes

2007-08-09 Thread Áron Sisak
This is (hopefully) the last of the debdiff series. All latest feisty, edgy and dapper has been tested in pbuilder. No "real testing" is given to either of them, though. ** Attachment added: "[edgy] debdiff" http://launchpadlibrarian.net/8743252/lighttpd_1.4.13%7Er1370-1ubuntu1.2.debdiff --

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
** Attachment added: "[dapper] debdiff" http://launchpadlibrarian.net/8741504/lighttpd_1.4.11-3ubuntu3.4.debdiff -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu.

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
tests/docroot/www/index.html~ is needed so that the test suite does not fail. -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bug

Re: [Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Kees Cook
On Wed, Aug 08, 2007 at 08:13:41PM -, Áron Sisak wrote: > BTW tests/docroot/www/index.html~ comes from upstream. Is it required to fix the problems? It appears to be an empty file. -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because y

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
** Attachment added: "[edgy] Two more issues fixed, CVE numbers listed." http://launchpadlibrarian.net/8740079/lighttpd_1.4.13%7Er1370-1ubuntu1.2.debdiff ** Changed in: lighttpd (Ubuntu Dapper) Importance: Undecided => High Assignee: (unassigned) => Áron Sisak Status: New => In

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
BTW tests/docroot/www/index.html~ comes from upstream. -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com http

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
Two more issues fixed, CVE numbers listed. ** Attachment added: "debdiff to fix CVEs 2007-3946 - 2007-3950" http://launchpadlibrarian.net/8739082/lighttpd_1.4.13-9ubuntu4.1.debdiff ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-3950 ** CVE added: http://www.cve.mitre.or

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Kees Cook
Thanks for preparing these diffs! Is the empty file tests/docroot/www/index.html~ actually supposed to be included? That seems like a backup file to me. Have these patches been runtime tested too? The changelog log looks great (very detailed!) the only thing I would change is to include the CVE

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-3949 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-3946 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-3947 -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
Edgy debdiff ** Attachment added: "[edgy] debdiff to provide security fixes" http://launchpadlibrarian.net/8736783/lighttpd_1.4.13%7Er1370-1ubuntu1.2.debdiff -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubunt

[Bug 127718] Re: lighttpd security fixes

2007-08-08 Thread Áron Sisak
Attached debdiff that provides security fixes. Trying in a feisty pbuilder now. ** Attachment added: "[feisty] debdiff to provide security fixes" http://launchpadlibrarian.net/8736547/lighttpd_1.4.13-9ubuntu4.1.debdiff -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You rece

[Bug 127718] Re: lighttpd security fixes

2007-07-25 Thread Scott Kitterman
** Changed in: lighttpd (Ubuntu) Importance: Low => High -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 127718] Re: lighttpd security fixes

2007-07-23 Thread Áron Sisak
** Changed in: lighttpd (Ubuntu) Assignee: (unassigned) => Áron Sisak ** Changed in: lighttpd (Ubuntu) Importance: Undecided => Low Status: New => In Progress -- lighttpd security fixes https://bugs.launchpad.net/bugs/127718 You received this bug notification because you are a mem