<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>14628</bug_id>
          
          <creation_ts>2003-01-27 11:28 0000</creation_ts>
          <short_desc>qt-dcgui security flaw</short_desc>
          <delta_ts>2003-02-05 04:28:47 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Applications</component>
          <version>1.4_rc2</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://dc.ketelhot.de/news.php</bug_file_loc>
          
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>biggms_1701@hotmail.com</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>vapier@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>biggms_1701@hotmail.com</who>
            <bug_when>2003-01-27 11:28:34 0000</bug_when>
            <thetext>As reported by the developers of qt-dcgui all versions before 0.2.2 have a 
security flaw that allows users to download unshared files.  The fix is to 
update to 0.2.2 or above.  Versions below 0.2.2 should be removed from portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>styx@gentoo.org</who>
            <bug_when>2003-01-27 14:22:57 0000</bug_when>
            <thetext>I&apos;ve committed 0.2.3 of dclib and qt-dcgui now. Aliz, are you going to write a GLSA 
on this one? </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2003-01-28 00:43:26 0000</bug_when>
            <thetext>you forgot to add the digest and patch files for dclib-2.3 ... ive added them now though ... </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>styx@gentoo.org</who>
            <bug_when>2003-01-28 05:29:05 0000</bug_when>
            <thetext>Ah, sorry. Being a gcc3 user, that just flew right by my testing. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aliz@gentoo.org</who>
            <bug_when>2003-02-05 04:28:47 0000</bug_when>
            <thetext>glsa sent </thetext>
          </long_desc>
      
    </bug>

</bugzilla>