Bug#689571: CVE-2012-4463: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files

2013-06-10 Thread Dmitry Smirnov
Hi Jonathan, Thank you for useful information and reminder. Unfortunately I did not succeed in isolating and backporting the fix for this issue. Upstream re-factored the code and that made patch too difficult to apply to previous versions at least at my competence level... Best wishes, Dmitry S

Bug#689571: CVE-2012-4463: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files

2013-06-10 Thread Jonathan Wiltshire
Package: mc Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.8) - use t

Bug#689571: [Pkg-mc-devel] Bug#689571: CVE-2012-4463: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files

2013-02-26 Thread Dmitry Smirnov
Hi Moritz, On Wed, 27 Feb 2013 09:18:59 Moritz Muehlenhoff wrote: > An upstream fix is now available, can you please merge this for Wheezy? > https://www.midnight-commander.org/ticket/2913 I already tried to backport but couldn't do it so far -- there are too many changes especially in post-buil

Bug#689571: CVE-2012-4463: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files

2013-02-26 Thread Moritz Muehlenhoff
On Thu, Oct 04, 2012 at 08:52:19AM +0200, Salvatore Bonaccorso wrote: > Package: mc > Version: 3:4.8.5-1~exp4 > Severity: important > Tags: security > > Hi, > the following vulnerability was published for mc. > > CVE-2012-4463[0]: > Improper sanitization of MC_EXT_SELECTED variable when viewing m

Bug#689571: CVE-2012-4463: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files

2012-10-03 Thread Salvatore Bonaccorso
Package: mc Version: 3:4.8.5-1~exp4 Severity: important Tags: security Hi, the following vulnerability was published for mc. CVE-2012-4463[0]: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files If you fix the vulnerability please also make sure to include the CVE (Comm