Bug#729065: ibus: CVE-2013-4509

2013-11-27 Thread Moritz Muehlenhoff
On Sun, Nov 17, 2013 at 05:35:31PM +0900, Osamu Aoki wrote:
> > It is my understanding that this needs to be fixed in various
> > Ibus engines. Please test the affected engines and clone/reassign 
> > this bug to the affected source packages.
> 
> Testing chinese input method is difficult for me :-)  Aron is busy with
> fcitx.  (I do not know how they work due to may lack of chinese skill).
> At this moment, we have not enough people for IM, so we are slow.

Please clone the bugs, so that it doesn't get lost.
 
> By the way, I can get fedora source as easily as ubuntu but openSUSE
> source ... I do not know where to begin.
> 
>   http://arm.koji.fedoraproject.org/koji/search (Fedora source info site)
>   https://wiki.debian.org/Repackage_srcrpm  (Method I use)
>   https://launchpad.net/(Ubuntu info site.)
> 
> Does anyoneu know where to find the latest suse source RPM are?

See here:
http://oss-security.openwall.org/wiki/distro-patches#opensuse-and-suse-linux

Cheers,
Moritz


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#729065: ibus: CVE-2013-4509

2013-11-17 Thread Osamu Aoki
Hi,

On Fri, Nov 08, 2013 at 02:41:25PM +0100, Moritz Muehlenhoff wrote:
> Hi,
> this has been assigned CVE-2013-4509
> https://groups.google.com/forum/#!topic/ibus-user/mvCHDO1BJUw
> 
> Some additional information can be found in the Novell bugzilla:
> https://bugzilla.novell.com/show_bug.cgi?id=847718

- ibus-mozc (fixed in 1.12.1599.102) in unstable now
- ibus-anthy (fixed in 1.5.4) in unstable now (I uploaded)
- ibus-pinyin  -- old so probably not yet fixed
- ibus-chewing -- old so probably not yet fixed
 ...

> It is my understanding that this needs to be fixed in various
> Ibus engines. Please test the affected engines and clone/reassign 
> this bug to the affected source packages.

Testing chinese input method is difficult for me :-)  Aron is busy with
fcitx.  (I do not know how they work due to may lack of chinese skill).
At this moment, we have not enough people for IM, so we are slow.

As I see novelle site, it also mention another bug for ibus:
https://bugzilla.redhat.com/show_bug.cgi?id=1013948

I will probably port fedora fixes once they are available.

By the way, I can get fedora source as easily as ubuntu but openSUSE
source ... I do not know where to begin.

  http://arm.koji.fedoraproject.org/koji/search (Fedora source info site)
  https://wiki.debian.org/Repackage_srcrpm  (Method I use)
  https://launchpad.net/(Ubuntu info site.)

Does anyoneu know where to find the latest suse source RPM are?

Regards,

Osamu


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#729065: ibus: CVE-2013-4509

2013-11-08 Thread Moritz Muehlenhoff
Package: ibus
Severity: important
Tags: security

Hi,
this has been assigned CVE-2013-4509
https://groups.google.com/forum/#!topic/ibus-user/mvCHDO1BJUw

Some additional information can be found in the Novell bugzilla:
https://bugzilla.novell.com/show_bug.cgi?id=847718

It is my understanding that this needs to be fixed in various
Ibus engines. Please test the affected engines and clone/reassign 
this bug to the affected source packages.

Cheers,
Moritz


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org