Bug#635549: Stable update of hplip for CVE-2011-2722 (#635549) ?

2012-01-15 Thread Adam D. Barratt
On Sun, 2011-12-11 at 18:02 +, Adam D. Barratt wrote: On Sun, 2011-12-04 at 17:26 +, Adam D. Barratt wrote: On Thu, 2011-12-01 at 20:17 +, Adam D. Barratt wrote: On Fri, 2011-11-25 at 14:58 +0100, Didier Raboud wrote: * Fix CVE-2011-2722 Insecure tempfile handling by

Bug#635549: Stable update of hplip for CVE-2011-2722 (#635549) ?

2011-12-11 Thread Adam D. Barratt
On Sun, 2011-12-04 at 17:26 +, Adam D. Barratt wrote: On Thu, 2011-12-01 at 20:17 +, Adam D. Barratt wrote: On Fri, 2011-11-25 at 14:58 +0100, Didier Raboud wrote: * Fix CVE-2011-2722 Insecure tempfile handling by patching the culprit code out. (Closes: #635549)

Bug#635549: Stable update of hplip for CVE-2011-2722 (#635549) ?

2011-12-04 Thread Adam D. Barratt
On Thu, 2011-12-01 at 20:17 +, Adam D. Barratt wrote: On Fri, 2011-11-25 at 14:58 +0100, Didier Raboud wrote: * Fix CVE-2011-2722 Insecure tempfile handling by patching the culprit code out. (Closes: #635549) I'm assuming the debug code isn't likely to be used that

Bug#635549: Stable update of hplip for CVE-2011-2722 (#635549) ?

2011-12-01 Thread Adam D. Barratt
On Fri, 2011-11-25 at 14:58 +0100, Didier Raboud wrote: after taking a closer look to #635549 and an IRC chat with the Security people, I propose to upload hplip to stable with the following changelog entry: hplip (3.10.6-2+squeeze0) stable; urgency=low Why +squeeze0? +squeeze1 is

Bug#635549: Stable update of hplip for CVE-2011-2722 (#635549) ?

2011-11-25 Thread Didier Raboud
Dear Release Team, after taking a closer look to #635549 and an IRC chat with the Security people, I propose to upload hplip to stable with the following changelog entry: hplip (3.10.6-2+squeeze0) stable; urgency=low * Fix CVE-2011-2722 Insecure tempfile handling by patching