Your message dated Wed, 21 Sep 2005 16:32:11 -0700
with message-id <[EMAIL PROTECTED]>
and subject line Bug#326976: fixed in py2play 0.1.8-1
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--------------------------------------
Received: (at submit) by bugs.debian.org; 6 Sep 2005 22:47:15 +0000
>From [EMAIL PROTECTED] Tue Sep 06 15:47:15 2005
Return-path: <[EMAIL PROTECTED]>
Received: from westfish.xiph.osuosl.org (westfish.xiph.org) [140.211.166.32]
by spohr.debian.org with esmtp (Exim 3.36 1 (Debian))
id 1ECmDj-00067X-00; Tue, 06 Sep 2005 15:47:15 -0700
Received: by westfish.xiph.org (Postfix, from userid 1015)
id 6D9851CB8F; Tue, 6 Sep 2005 15:47:15 -0700 (PDT)
Date: Tue, 6 Sep 2005 15:47:15 -0700
From: Arc <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Cc: Marc Dequnes <[EMAIL PROTECTED]>
Subject: py2play security vulnerability
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.5.9i
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level:
X-Spam-Status: No, hits=-5.1 required=4.0 tests=BAYES_44,HAS_PACKAGE
autolearn=no version=2.60-bugs.debian.org_2005_01_02
Package: py2play
Version: 0.1.7-1
py2play uses Python pickle for sharing Soya objects (or other classes)
over a P2P network. Pickle objects, when unpickled, contain both data
and code. A malicious user on a game's P2P net can send custom classes
to fellow players in order to gain access to their systems or execute
malicious commands.
There is no fix to this, this flaw is at py2play's core. The maintainer
of this package has been aware of this security flaw for some time and
has not only ignored it, but replaced it with a new module called "tofu"
which has the same vulnerability.
At a minimum, users of this Python module need to be aware of this.
--
Diversity is the Fuel of Evolution,
Conformity it's Starvation.
Be Radical. Be New. Be Different.
Feed Evolution with Everything You Are.
---------------------------------------
Received: (at 326976-close) by bugs.debian.org; 21 Sep 2005 23:45:40 +0000
>From [EMAIL PROTECTED] Wed Sep 21 16:45:40 2005
Return-path: <[EMAIL PROTECTED]>
Received: from katie by spohr.debian.org with local (Exim 3.36 1 (Debian))
id 1EIE4R-00024Y-00; Wed, 21 Sep 2005 16:32:11 -0700
From: =?utf-8?b?TWFyYyBEZXF1w6huZXMgKER1Y2sp?= <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.56 $
Subject: Bug#326976: fixed in py2play 0.1.8-1
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Wed, 21 Sep 2005 16:32:11 -0700
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level:
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER
autolearn=no version=2.60-bugs.debian.org_2005_01_02
Source: py2play
Source-Version: 0.1.8-1
We believe that the bug you reported is fixed in the latest version of
py2play, which is due to be installed in the Debian FTP archive:
py2play_0.1.8-1.diff.gz
to pool/main/p/py2play/py2play_0.1.8-1.diff.gz
py2play_0.1.8-1.dsc
to pool/main/p/py2play/py2play_0.1.8-1.dsc
py2play_0.1.8.orig.tar.gz
to pool/main/p/py2play/py2play_0.1.8.orig.tar.gz
python-2play_0.1.8-1_all.deb
to pool/main/p/py2play/python-2play_0.1.8-1_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Marc Dequènes (Duck) <[EMAIL PROTECTED]> (supplier of updated py2play package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 21 Sep 2005 22:57:42 +0200
Source: py2play
Binary: python-2play
Architecture: source all
Version: 0.1.8-1
Distribution: unstable
Urgency: high
Maintainer: Marc Dequènes (Duck) <[EMAIL PROTECTED]>
Changed-By: Marc Dequènes (Duck) <[EMAIL PROTECTED]>
Description:
python-2play - peer-to-peer network game engine
Closes: 326976
Changes:
py2play (0.1.8-1) unstable; urgency=high
.
* Security fix (network mode disabled)(CAN-2005-2875)
(Closes: #326976).
* Fix FSF address in 'debian/copyright'.
Files:
33a793afd4f6dc95a236af7a17737d7a 608 python optional py2play_0.1.8-1.dsc
2d82c0ffbe48094e6027de898fc6a554 21515 python optional
py2play_0.1.8.orig.tar.gz
5aa45164d19ba44d22094eb23c803d2b 2088 python optional py2play_0.1.8-1.diff.gz
0810e0d459c91dee6a5adedc15d43f39 17784 python optional
python-2play_0.1.8-1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iD8DBQFDMcl6sczZcpAmcIYRAif1AJ4lF7c3Z3T6/+eu2y+i+plJxYpX2gCgnG9O
1yLGHx8OF2GSTm4bhSwf71M=
=YTug
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]