dev-python/nautilus-python Untrusted search path vulnerability (CVE-2009-0317)

Bug #333915 reported by Christian Faulhammer
254
Affects Status Importance Assigned to Milestone
Gentoo Overlay for Bazaar
Fix Released
Critical
Mark Lee
nautilus-python
Fix Released
Medium
Gentoo Linux
Fix Released
Low

Bug Description

I gathered some information in http://bugs.gentoo.org/show_bug.cgi?id=257011, please mask dev-python/nautilus-python for now and then try to find a fix.

Revision history for this message
Mark Lee (malept) wrote :

Fixed in r214.

Changed in bzr-gentoo-overlay:
assignee: nobody → malept
importance: Undecided → Critical
status: New → Fix Released
status: Fix Released → Fix Committed
Revision history for this message
Mark Lee (malept) wrote :

Added a patch in r216 that I have forwarded upstream.

Changed in nautilus-python:
status: Unknown → New
Changed in bzr-gentoo-overlay:
status: Fix Committed → Fix Released
Revision history for this message
Mark Lee (malept) wrote :

FWIW, this has been fixed upstream in nautilus-python-0.6.0.

visibility: private → public
Changed in nautilus-python:
importance: Unknown → Medium
status: New → Fix Released
Changed in gentoo:
importance: Unknown → Low
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.