Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 167535
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Daniel Black <dragonheart@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tiziano Müller <dev-zero@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 167535 depends on: Show dependency tree
Bug 167535 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-02-18 21:13 0000
From the ChangeLog:

2007-01-09: lftp-3.5.9 released. Fixed a potential security vulnerability in
mirror --script.
 2006-12-28: lftp-3.5.8 released. Fixed sleep command.
 2006-12-08: lftp-3.5.7 released. Fixed a spurious timeout when uploading a
file.
[...]

Therefore it might be a good idea to directly mark the new version stable.

------- Comment #1 From Daniel Black 2007-02-19 08:39:30 0000 -------
------> /usr/share/doc/lftp-3.5.9/NEWS.bz2 <------
Version 3.5.9 - 2007-01-09

* fixed `mirror --script' which generated improperly quoted shell commands
(potential security vulnerability, when someone executes the resulting script).

I'm not considering this a real security vulerability. The announce would
probably look like "If a user runs a lftp mirror scripted by someone else they
could arbitarliy execute code". Feel free to disagree.

Otherwise - stable in 30 days.

------- Comment #2 From Daniel Black 2007-05-06 11:01:34 0000 -------
opps - must of been forgetting stuff. seems fixed in bug 173524

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug