Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Thijs Kinkhorst
On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: Uploaded. Thanks! But... can't find the upload anywhere? Maybe something went wrong or am I looking the wrong way? Thijs -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Jeroen van Wolffelaar
On Tue, May 30, 2006 at 09:55:16AM +0200, Thijs Kinkhorst wrote: On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: Uploaded. Thanks! But... can't find the upload anywhere? Maybe something went wrong or am I looking the wrong way? I got a 'upload removed due to not being signed by

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Steve Kemp
On Tue, May 30, 2006 at 07:14:11PM +0200, Jeroen van Wolffelaar wrote: On Tue, May 30, 2006 at 09:55:16AM +0200, Thijs Kinkhorst wrote: On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: Uploaded. Thanks! But... can't find the upload anywhere? Maybe something went wrong or am I

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-30 Thread Jeroen van Wolffelaar
On Tue, May 30, 2006 at 06:21:39PM +0100, Steve Kemp wrote: On Tue, May 30, 2006 at 07:14:11PM +0200, Jeroen van Wolffelaar wrote: On Tue, May 30, 2006 at 09:55:16AM +0200, Thijs Kinkhorst wrote: On Sun, 2006-05-28 at 22:11 +0100, Steve Kemp wrote: Uploaded. Thanks! But... can't

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-28 Thread Thijs Kinkhorst
On Tue, 2006-05-23 at 12:36 +0200, Thijs Kinkhorst wrote: Problem is that Jeroen announced that he's on a trip through Mexico now, so I'm left without someone to upload. Maybe the (testing) security team or any other DD interested in getting this bug fixed, can take a look and upload?

Bug#365533: [Secure-testing-team] Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-28 Thread Steve Kemp
On Sun, May 28, 2006 at 11:02:18PM +0200, Thijs Kinkhorst wrote: On Tue, 2006-05-23 at 12:36 +0200, Thijs Kinkhorst wrote: Problem is that Jeroen announced that he's on a trip through Mexico now, so I'm left without someone to upload. Maybe the (testing) security team or any other DD

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-23 Thread Thijs Kinkhorst
tags 365533 pending thanks On Thu, 2006-05-18 at 05:21 +0200, Moritz Muehlenhoff wrote: W.r.t. unstable, I will look into that very soon, we'll need to be upgrading to a new upstream aswell. I'll check whether that can be done in the short term, if not, I'll prepare a patched package.

Processed: Re: Bug#365533: CVE-2006-1896: Admin command execution

2006-05-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 365533 pending Bug#365533: CVE-2006-1896: Admin command execution Tags were: patch security Tags added: pending thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-17 Thread Thijs Kinkhorst
On Mon, 2006-05-15 at 08:31 +0200, Jeroen van Wolffelaar wrote: On Wed, May 03, 2006 at 10:56:33AM +0200, Thijs Kinkhorst wrote: Thanks for the report. While I think that people who are admin can already do a lot of damage and should hence be considered trusted, executing php code is a step

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-17 Thread Moritz Muehlenhoff
Thijs Kinkhorst wrote: On Mon, 2006-05-15 at 08:31 +0200, Jeroen van Wolffelaar wrote: On Wed, May 03, 2006 at 10:56:33AM +0200, Thijs Kinkhorst wrote: Thanks for the report. While I think that people who are admin can already do a lot of damage and should hence be considered trusted,

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-15 Thread Jeroen van Wolffelaar
tags 365533 patch thanks On Wed, May 03, 2006 at 10:56:33AM +0200, Thijs Kinkhorst wrote: Thanks for the report. While I think that people who are admin can already do a lot of damage and should hence be considered trusted, executing php code is a step further in permissions and thus this can

Bug#365533: CVE-2006-1896: Admin command execution

2006-05-03 Thread Thijs Kinkhorst
On Sun, 2006-04-30 at 21:31 +0200, Stefan Fritsch wrote: Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the

Bug#365533: CVE-2006-1896: Admin command execution

2006-04-30 Thread Stefan Fritsch
Package: phpbb2 Severity: grave Tags: security Justification: user security hole CVE-2006-1896: Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or