Bug#480972: vulnerable to symlink attacks

2008-05-21 Thread Nico Golde
Hi Sune, * Sune Vuorela [EMAIL PROTECTED] [2008-05-18 21:35]: On Tuesday 13 May 2008, Marco d'Itri wrote: Security team: libuu-dev is a static-only library (see #216593). klibido, nget and slrn build-depend on libuu-dev, while libconvert-uulib-perl and kde (I don't know exactly which

Bug#480972: vulnerable to symlink attacks

2008-05-21 Thread Sune Vuorela
On Thursday 22 May 2008, Nico Golde wrote: Yes, same here. Looks like some deprecated package for kde libs. I couldn't find that either in current source packages. Marco, where did you get this information? Marco told me he got it from google code search. /Sune -- Man, do you know how could

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Marco d'Itri
Do you have any objections to me making a NMU to fix this bug AND to make the package generate a proper shared library? -- ciao, Marco signature.asc Description: Digital signature

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread gregor herrmann
On Tue, 13 May 2008 01:19:19 +0200, Marco d'Itri wrote: Security team: libuu-dev is a static-only library (see #216593). klibido, nget and slrn build-depend on libuu-dev, while libconvert-uulib-perl and kde (I don't know exactly which package, look in the kdesupport directory) contain an

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Nico Golde
Hi Gregor, * gregor herrmann [EMAIL PROTECTED] [2008-05-18 15:40]: On Tue, 13 May 2008 01:19:19 +0200, Marco d'Itri wrote: Security team: libuu-dev is a static-only library (see #216593). klibido, nget and slrn build-depend on libuu-dev, while libconvert-uulib-perl and kde (I don't know

Bug#480972: vulnerable to symlink attacks

2008-05-18 Thread Sune Vuorela
On Tuesday 13 May 2008, Marco d'Itri wrote: Security team: libuu-dev is a static-only library (see #216593). klibido, nget and slrn build-depend on libuu-dev, while libconvert-uulib-perl and kde (I don't know exactly which package, look in the kdesupport directory) contain an embedded copy.

Bug#480972: vulnerable to symlink attacks

2008-05-12 Thread Marco d'Itri
Package: libuu-dev Version: 0.5.20-3 Severity: critical Tags: security upstream Security team: libuu-dev is a static-only library (see #216593). klibido, nget and slrn build-depend on libuu-dev, while libconvert-uulib-perl and kde (I don't know exactly which package, look in the kdesupport