1.53 should be merged

Bug #375230 reported by Charles Kerr
264
This bug affects 1 person
Affects Status Importance Assigned to Milestone
transmission (Ubuntu)
Invalid
Medium
Krzysztof Klimonda
Nominated for Hardy by Dimitri John Ledkov
Nominated for Intrepid by Dimitri John Ledkov
Nominated for Jaunty by Hew

Bug Description

Binary package hint: transmission

Since 9.04 is using the Transmission 1.5x series, it should be updated to use 1.53, which was released today.

1.53 only has two changes from 1.52. One is a minor locale fix in the JSON parser, but the other closes a potential CSRF security hole for users who access Transmission via a web browser.

Thanks for your consideration.

CVE References

visibility: private → public
Changed in transmission (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Changed in transmission (Ubuntu):
assignee: nobody → Krzysztof Klimonda (kklimonda)
status: Confirmed → In Progress
Revision history for this message
Charles Kerr (charlesk) wrote :

This has been in progress for two months now.

It's my understanding that some of the holdup is because there are changes between 1.51 and 1.53 that focus on, for example, indentation cleanup rather than pure bug fixes.

Is there anything upstream can do to make the 1.51 -> 1.53 jump easier to swallow?

As an aside, 1.53 has had some burn-in time for Mac OS X 10.4 users... 1.60 and above require OS X 10.5.

Revision history for this message
Charles Kerr (charlesk) wrote :

Oops, 1 month != 2 months :)

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

This CVE is marked "low" in our CVE tracker, which means we'll usually wait until there is a more serious issue before releasing security updates.

That being said, if someone attaches a debdiff containing a backported patch, we'll gladly sponsor it.

Kees Cook (kees)
Changed in transmission (Ubuntu):
status: In Progress → Triaged
Revision history for this message
Charles Kerr (charlesk) wrote :

Closing since 9.04 has reached EOL

Changed in transmission (Ubuntu):
status: Triaged → Incomplete
Revision history for this message
Vish (vish) wrote :

Fully closing the bug.. :-)

Changed in transmission (Ubuntu):
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.