Bug#873439: [pkg-fgfs-crew] Bug#873439: flightgear: CVE-2017-13709: Incorrect access control

2017-09-01 Thread Markus Wanner
Hi, while this has been fixed in unstable, I have also requested to upload to stable and unstable. Here are the issues and versions for reference: stable:#873754 1:2016.4.4+dfsg-3+deb9u1 oldstable: #873877 3.0.0-5+deb8u3 Assuming the release team approves the uploads, the fix should enter

Bug#873439: [pkg-fgfs-crew] Bug#873439: flightgear: CVE-2017-13709: Incorrect access control

2017-08-28 Thread Florent Rougon
Hi, For stretch, the last two commits of upstream branch release/2016.4: https://sourceforge.net/p/flightgear/flightgear/ci/release/2016.4/~/tree/ should do the job (as already said in other mails, and ditto for unstable with the release/2017.2 branch). For jessie (it's also affected), I

Bug#873439: flightgear: CVE-2017-13709: Incorrect access control

2017-08-27 Thread Salvatore Bonaccorso
Source: flightgear Version: 1:2017.2.1+dfsg-3 Severity: grave Tags: upstream security Hi, the following vulnerability was published for flightgear. CVE-2017-13709[0]: | In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger | subsystem allows one to overwrite any file via a