Secure testing team - Sep 2008

Tuesday September 30 2008
TimeRepliesSubject
4:28PM 0 Bug#500707: Does not run as the maradns user/group
11:51AM 0 Bug#500683: CVE-2008-3827: integer overflows
 
Monday September 29 2008
TimeRepliesSubject
6:10PM 0 Bug#500611: jumpnbump: insecure use of /tmp
2:41PM 9 Please unblock gallery 1.5.9-1
 
Sunday September 28 2008
TimeRepliesSubject
8:45AM 1 please remove convirt and cgiwrap from testing
 
Saturday September 27 2008
TimeRepliesSubject
3:38AM 1 please unblock faad2
12:17AM 0 Bug#500295: possible script injection via /etc/wordpress/wp-config.php
 
Thursday September 25 2008
TimeRepliesSubject
7:17PM 0 Bug#500181: chillispot: symlink attack can be launched via postinst
7:12PM 0 Bug#500180: debtorrent: symlink attack can be launched via postinst
 
Wednesday September 24 2008
TimeRepliesSubject
9:47PM 0 Bug#500087: CVE-2008-4107: The rand and mt_rand functions in PHP produce weak random numbers
 
Tuesday September 23 2008
TimeRepliesSubject
8:54PM 0 Bug#499942: CVE-2008-3663: Squirrelmail: Session hijacking vulnerability
1:27PM 0 Bug#499899: fraad2: heap overflow
 
Monday September 22 2008
TimeRepliesSubject
7:51AM 0 Bug#499771: webkit: several vulnerabilities (CVE-2008-3950 CVE-2008-3632)
4:08AM 0 REGARD,MR BAMBANG SUHARTO
 
Sunday September 21 2008
TimeRepliesSubject
10:02AM 3 embedded exo copy in pcmanfm
 
Friday September 19 2008
TimeRepliesSubject
9:06PM 0 Bug#499568: emacs22-common: CVE-2008-3949: Interactive Python Session loads module from current directory
 
Sunday September 14 2008
TimeRepliesSubject
11:45AM 0 Bug#498901: Unsecure use of temporary files
11:05AM 0 Bug#498899: Unsecure use of temporary files
10:41AM 2 please unblock nfdump
9:49AM 0 please unblock bitlbee
9:43AM 0 please unblock mon
 
Saturday September 13 2008
TimeRepliesSubject
3:29AM 0 Bug#498768: libxml2: does not correctly handle long entity names (CVE-2008-3529)
2:59AM 0 Bug#498764: ffmpeg-debian: vulnerable to denial-of-service attack (CVE-2008-3230)
 
Tuesday September 9 2008
TimeRepliesSubject
12:45PM 0 Bug#498362: mysql-common: DoS via empty bit-string literal (b'')
 
Monday September 8 2008
TimeRepliesSubject
12:17PM 0 Bug#498243: xine-lib: multiple heap overflows
11:50AM 0 Bug#498236: libpam-modules: Login incorrect message after entering non-existent login name
 
Friday September 5 2008
TimeRepliesSubject
8:03AM 0 Bug#497894: vlc: CVE-2008-3732 Integer overflow in the Open function in modules/demux/tta.c
3:31AM 0 Bug#497878: wireshark: several security issues
 
Thursday September 4 2008
TimeRepliesSubject
7:56PM 0 Bug#497835: gmanedit: Found several buffer overflows
 
Wednesday September 3 2008
TimeRepliesSubject
9:18PM 0 Bug#497730: dns2tcp contains a buffer overflow
9:54AM 0 Bug#497640: zoneminder: Several security issues (XSS, SQL injection, Command injection)
6:20AM 0 Bug#497622: runs along after package removal
 
Tuesday September 2 2008
TimeRepliesSubject
6:12PM 3 packages fixed in testing-security still show in rc bug list
6:03PM 3 security issue unblocks
1:23PM 0 A SIEMENS tem algo de melhor para lhe oferecer!!!
 
Monday September 1 2008
TimeRepliesSubject
8:26PM 0 Bug#497452: nfdump: vulnerable to symlink attacks