[Bug 1509835] Re: Possible Shell Command Injection

2015-11-22 Thread SYEDFAYAZ MUJAWAR
** Changed in: apt-offline (Ubuntu) Assignee: (unassigned) => SYEDFAYAZ MUJAWAR (syedfayaz28) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1509835 Title: Possible Shell Command Injection To m

[Bug 1509835] Re: Possible Shell Command Injection

2015-10-31 Thread Bernd Dietzel
My improved Patch Nr. 2 ** Patch added: "This patch can split the opts string and has a stdout and a stderr" https://bugs.launchpad.net/ubuntu/+source/apt-offline/+bug/1509835/+attachment/4509935/+files/Patch2.diff -- You received this bug notification because you are a member of Ubuntu Bug

[Bug 1509835] Re: Possible Shell Command Injection

2015-10-31 Thread Bernd Dietzel
my demo exploit video (german) https://www.youtube.com/watch?v=QGAjwKF5d3w -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1509835 Title: Possible Shell Command Injection To manage notifications abou

[Bug 1509835] Re: Possible Shell Command Injection

2015-10-30 Thread Bernd Dietzel
My patch was accepted by Mr. Sarraf and fixed in apt-offline upstream repo. https://github.com/rickysarraf/apt-offline/blob/master/apt_offline_core/AptOfflineCoreLib.py -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.laun

[Bug 1509835] Re: Possible Shell Command Injection

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1509835] Re: Possible Shell Command Injection

2015-10-26 Thread Bernd Dietzel
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1509835 Title: Possible Shell Command Injection To manage notifications about this bug go to

[Bug 1509835] Re: Possible Shell Command Injection

2015-10-25 Thread Ubuntu Foundations Team Bug Bot
The attachment "Patch for AptOfflineCoreLib.py" seems to be a patch. If it isn't, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are a member of the ~ubuntu-reviewers, unsubscribe the team. [This is an automated message performed by a Launchpad user owned b