please sync from debian (unstable) 2.0.11-1 - security vulnerability

Bug #657035 reported by David Sugar
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
babiloo (Ubuntu)
Fix Released
Undecided
Unassigned
Maverick
Won't Fix
Undecided
Unassigned
Natty
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: babiloo

Per http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=591995 and http://security-tracker.debian.org/tracker/CVE-2007-4559 there is a local exploit related to predictable naming of /tmp files. This is fixed in debian in 2.0.11. I have been able to build 2.0.11 from sid on Maverick, it is a minor update from 2.0.9 which we currently carry, and we have no ubuntu specific patches to consider.

visibility: private → public
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in babiloo (Ubuntu):
status: New → Confirmed
Revision history for this message
Marco Rodrigues (gothicx) wrote :
Changed in babiloo (Ubuntu Natty):
status: Confirmed → Fix Released
Changed in babiloo (Ubuntu Maverick):
status: New → Confirmed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. maverick has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against maverick is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in babiloo (Ubuntu Maverick):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.