Marking bug as public, since the issue is public now. I have uploaded untested hardy packages for this and the other CVE that affects hardy to https://launchpad.net/~ubuntu-security-proposed/+archive/ppa/+packages. These patches came from upstream and applied cleanly. Since this is in universe, can somebody test these on Hardy? Once this is done, I will be happy to push it to hardy-security.
** Tags added: security-verification -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/861182 Title: Remote directory traversal, allows write to arbitrary locations To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/puppet/+bug/861182/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs