[Bug 661416] Re: Uncontrolled XMLHTTPRequest vulnerability

2010-10-25 Thread Launchpad Bug Tracker
This bug was fixed in the package kdelibs - 4:3.5.10.dfsg.1-3ubuntu2.10.04.1 --- kdelibs (4:3.5.10.dfsg.1-3ubuntu2.10.04.1) lucid-security; urgency=low * SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability. (LP: #661416) - Ark and KMail performs insufficient validation

[Bug 661416] Re: Uncontrolled XMLHTTPRequest vulnerability

2010-10-25 Thread Launchpad Bug Tracker
This bug was fixed in the package kdelibs - 4:3.5.10.dfsg.1-3ubuntu2.10.10.1 --- kdelibs (4:3.5.10.dfsg.1-3ubuntu2.10.10.1) maverick-security; urgency=low * SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability. (LP: #661416) - Ark and KMail performs insufficient

[Bug 661416] Re: Uncontrolled XMLHTTPRequest vulnerability

2010-10-22 Thread Steve Beattie
Thanks, I've done some local test builds and have uploaded these to the ubuntu-security-proposed ppa https://launchpad.net/~ubuntu-security- proposed/+archive/ppa/ and will release them to the lucid and maverick security pocket soon. ** Changed in: kdelibs (Ubuntu Lucid) Status: Confirmed

[Bug 661416] Re: Uncontrolled XMLHTTPRequest vulnerability

2010-10-15 Thread Felix Geyer
kdelibs (4:3.5.10.dfsg.1-3ubuntu2.10.10.1) maverick-security; urgency=low * SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability. (LP: #661416) - Ark and KMail performs insufficient validation which leads to specially crafted archive files, using unknown MIME types, to be

[Bug 661416] Re: Uncontrolled XMLHTTPRequest vulnerability

2010-10-15 Thread Felix Geyer
kdelibs (4:3.5.10.dfsg.1-3ubuntu2.10.04.1) lucid-security; urgency=low * SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability. (LP: #661416) - Ark and KMail performs insufficient validation which leads to specially crafted archive files, using unknown MIME types, to be