Bug#746593: rxvt-unicode: CVE-2014-3121: user-assisted arbitrary commands execution

2014-05-02 Thread Ryan Kavanagh
Hi,

On Fri, May 02, 2014 at 08:48:28AM +0200, Moritz Muehlenhoff wrote:
> > the following vulnerability was published for rxvt-unicode.
> > 
> > CVE-2014-3121[0]: user-assisted arbitrary commands execution
> 
> Can you backport the change to oldstable-security and stable-security?

Thanks for the heads up. I plan on uploading rxvt-unicode to unstable
today, and will work on having the changes for oldstable/stable ready by
tomorrow.

Best wishes,
Ryan


signature.asc
Description: Digital signature


Bug#746593: rxvt-unicode: CVE-2014-3121: user-assisted arbitrary commands execution

2014-05-02 Thread Moritz Muehlenhoff
On Thu, May 01, 2014 at 08:32:02PM +0200, Salvatore Bonaccorso wrote:
> Source: rxvt-unicode
> Severity: grave
> Tags: security upstream fixed-upstream
> Justification: user security hole
> 
> Hi,
> 
> the following vulnerability was published for rxvt-unicode.
> 
> CVE-2014-3121[0]:
> user-assisted arbitrary commands execution

More information can be found in the report on oss-security:
http://seclists.org/oss-sec/2014/q2/204

Can you backport the change to oldstable-security and stable-security?

Cheers,
Moritz


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#746593: rxvt-unicode: CVE-2014-3121: user-assisted arbitrary commands execution

2014-05-01 Thread Salvatore Bonaccorso
Source: rxvt-unicode
Severity: grave
Tags: security upstream fixed-upstream
Justification: user security hole

Hi,

the following vulnerability was published for rxvt-unicode.

CVE-2014-3121[0]:
user-assisted arbitrary commands execution

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3121
https://security-tracker.debian.org/tracker/CVE-2014-3121

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org