Bug#696816: jenkins: Security issues were found in Jenkins core

2013-01-29 Thread James Page
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Steve On 25/01/13 15:18, Steven McDonald wrote: > The issue was raised on debian-devel[0] that this bug still > affects unstable and is causing jenkins to be a candidate for > removal from wheezy. I have backported the fixes for these issues > fr

Bug#696816: jenkins: Security issues were found in Jenkins core

2013-01-25 Thread Steven McDonald
Hi there, The issue was raised on debian-devel[0] that this bug still affects unstable and is causing jenkins to be a candidate for removal from wheezy. I have backported the fixes for these issues from upstream git; they are attached to this e-mail as separate quilt patches for the sake of cleanl

Processed: Re: Bug#696816: jenkins: Security issues were found in Jenkins core

2012-12-29 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > clone 696816 -1 Bug #696816 [jenkins] jenkins: Security issues were found in Jenkins core Bug 696816 cloned as bug 696974 > reassign -1 jenkins-winstone 0.9.10-jenkins-37+dfsg-1 Bug #696974 [jenkins] jenkins: Security issues were found in Jenkins

Bug#696816: jenkins: Security issues were found in Jenkins core

2012-12-29 Thread Nobuhiro Ban
clone 696816 -1 reassign -1 jenkins-winstone 0.9.10-jenkins-37+dfsg-1 thanks Dear Maintainer, I found upstream "SECURITY-44" (aka CVE-2012-6072) was from Winstone, and it might be fixed in 0.9.10-jenkins-40. https://github.com/jenkinsci/jenkins/commit/ad084edb571555e7c5a9bc5b27aba09aac8da98d >[

Bug#696816: jenkins: Security issues were found in Jenkins core

2012-12-28 Thread Salvatore Bonaccorso
Hi On Fri, Dec 28, 2012 at 01:17:46AM +0900, Nobuhiro Ban wrote: > Package: jenkins > Version: 1.447.2+dfsg-2 > Severity: grave > Tags: security > > Dear Maintainer, > > The upstream vendor announced a security advisory, that is rated high > severity. > > See: > https://wiki.jenkins-ci.org/di