[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: KDE Security Advisory: URI Handler Vulnerabilities



On Mon, May 17, 2004 at 09:01:24PM +0200, Martin Schulze wrote:
> Hi,
> 
> could you tell me which version of kdelibs, kdenetwork (or another
> package if another one is affected) fixes this problem in unstable?
> 
> http://www.kde.org/info/security/advisory-20040517-1.txt
> 
> If you apply the patch, please mention CAN-2004-0411 in the
> changelog file so we can easier track this security problem.

As far as I know it hasn't been fixed yet. I am planning to fix it soon,
the problem is that we already know that kdelibs is going to be broken
again in the next week with the new libcupsys2-gnutls10 upload since no
one every cares to provide oldlibs (gar). I had hoped that the new cups
library would have been allowed into sid this past weekend so I could
have just done one upload instead of hammering the buildds twice with
kdelibs. But from what I have heard AJ stalled it. So I guess I will be
forced to do two uploads. As always I am going to pull current
KDE_3_2_BRANCH for the upload.

Thanks,
Chris

Attachment: signature.asc
Description: Digital signature


Reply to: