[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#294271: marked as done (IDN support allows domain name spoofing)



Your message dated Mon, 28 Feb 2005 09:50:59 -0500
with message-id <E1D5mEd-0002dS-00@newraff.debian.org>
and subject line Bug#294271: fixed in kdelibs 4:3.3.2-3
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 8 Feb 2005 21:04:28 +0000
>From joey@kitenet.net Tue Feb 08 13:04:28 2005
Return-path: <joey@kitenet.net>
Received: from kitenet.net [64.62.161.42] (postfix)
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1CycX6-0000Nc-00; Tue, 08 Feb 2005 13:04:28 -0800
Received: from dragon.kitenet.net (unknown [66.168.94.144])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(Client CN "Joey Hess", Issuer "Joey Hess" (verified OK))
	by kitenet.net (Postfix) with ESMTP id 9EC8A18045
	for <submit@bugs.debian.org>; Tue,  8 Feb 2005 21:04:10 +0000 (GMT)
Received: by dragon.kitenet.net (Postfix, from userid 1000)
	id D02006E20E; Tue,  8 Feb 2005 16:05:55 -0500 (EST)
Date: Tue, 8 Feb 2005 16:05:55 -0500
From: Joey Hess <joeyh@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: IDN support allows domain name spoofing
Message-ID: <[🔎] 20050208210555.GA30829@kitenet.net>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="WIyZ46R2i8wDzkSu"
Content-Disposition: inline
X-Reportbug-Version: 3.7.1
User-Agent: Mutt/1.5.6+20040907i
Delivered-To: submit@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 


--WIyZ46R2i8wDzkSu
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Package: konqueror
Severity: normal
Tags: security

konqueror and other browsers which support IDN are vulnerable to domain
spoofing via homograph characters in domain names. Please see
http://lists.netsys.com/pipermail/full-disclosure/2005-February/031459.html
for details, and note that this is CAN-2005-0237.

Note: I have not marked this bug as releae critical, because it's not
clear to me if spoofing attacks qualify.

--=20
see shy jo

--WIyZ46R2i8wDzkSu
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQFCCSmzd8HHehbQuO8RAs+QAJ46Dk6dchu0gBSz9GJ9d0LUwS5gLQCfcjMg
De9OcWGoL32I8NG+eW39Yus=
=TzTR
-----END PGP SIGNATURE-----

--WIyZ46R2i8wDzkSu--

---------------------------------------
Received: (at 294271-close) by bugs.debian.org; 28 Feb 2005 14:53:18 +0000
>From katie@ftp-master.debian.org Mon Feb 28 06:53:18 2005
Return-path: <katie@ftp-master.debian.org>
Received: from newraff.debian.org [208.185.25.31] (mail)
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1D5mGs-0000We-00; Mon, 28 Feb 2005 06:53:18 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
	id 1D5mEd-0002dS-00; Mon, 28 Feb 2005 09:50:59 -0500
From: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
To: 294271-close@bugs.debian.org
X-Katie: $Revision: 1.55 $
Subject: Bug#294271: fixed in kdelibs 4:3.3.2-3
Message-Id: <E1D5mEd-0002dS-00@newraff.debian.org>
Sender: Archive Administrator <katie@ftp-master.debian.org>
Date: Mon, 28 Feb 2005 09:50:59 -0500
Delivered-To: 294271-close@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 
X-CrossAssassin-Score: 3

Source: kdelibs
Source-Version: 4:3.3.2-3

We believe that the bug you reported is fixed in the latest version of
kdelibs, which is due to be installed in the Debian FTP archive:

kdelibs-bin_3.3.2-3_i386.deb
  to pool/main/k/kdelibs/kdelibs-bin_3.3.2-3_i386.deb
kdelibs-data_3.3.2-3_all.deb
  to pool/main/k/kdelibs/kdelibs-data_3.3.2-3_all.deb
kdelibs4-dev_3.3.2-3_i386.deb
  to pool/main/k/kdelibs/kdelibs4-dev_3.3.2-3_i386.deb
kdelibs4-doc_3.3.2-3_all.deb
  to pool/main/k/kdelibs/kdelibs4-doc_3.3.2-3_all.deb
kdelibs4_3.3.2-3_i386.deb
  to pool/main/k/kdelibs/kdelibs4_3.3.2-3_i386.deb
kdelibs_3.3.2-3.diff.gz
  to pool/main/k/kdelibs/kdelibs_3.3.2-3.diff.gz
kdelibs_3.3.2-3.dsc
  to pool/main/k/kdelibs/kdelibs_3.3.2-3.dsc
kdelibs_3.3.2-3_all.deb
  to pool/main/k/kdelibs/kdelibs_3.3.2-3_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 294271@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> (supplier of updated kdelibs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Mon, 28 Feb 2005 14:05:30 +0100
Source: kdelibs
Binary: kdelibs4 kdelibs-bin kdelibs kdelibs4-doc kdelibs-data kdelibs4-dev
Architecture: source i386 all
Version: 4:3.3.2-3
Distribution: unstable
Urgency: high
Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Changed-By: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Description: 
 kdelibs    - KDE core libraries metapackage
 kdelibs-bin - KDE core binaries
 kdelibs-data - KDE core shared data
 kdelibs4   - KDE core libraries
 kdelibs4-dev - KDE core libraries (development files)
 kdelibs4-doc - KDE core library documentation
Closes: 292085 294204 294271 297095
Changes: 
 kdelibs (4:3.3.2-3) unstable; urgency=high
 .
   * Urgency high as it closes a security RC bug
 .
   +++ Changes by Isaac Clerencia:
 .
   * Fix syntax error in dcopidlng, closes: #297095 (was causing kdepim an
     others to FTBFS).
 .
   * Apply patch from KDE 3.4 to fix CAN-2005-0237 (spoofing using IDN),
     closes: #294271, #294204. IDN is now disabled in all KDE apps unless
     the environment variable KDE_USE_IDN is set.
 .
   * Christopher Cheney has kindly relicensed man pages written by him from
     GDFL to GPL, update the license statement accordingly. Closes: #292085.
Files: 
 f7eb7e75e030f3df1053e9a1250c739c 1302 libs optional kdelibs_3.3.2-3.dsc
 ee097e54514e5524d18bf8a4600e1a69 443362 libs optional kdelibs_3.3.2-3.diff.gz
 f03e9ee4f79db9662b1a3e123cfee4d6 855214 libs optional kdelibs-bin_3.3.2-3_i386.deb
 1b5e317c639495e5d802ddd5d94d8142 8187008 libs optional kdelibs4_3.3.2-3_i386.deb
 bbf8f638a6be032355aa2e0eb1315e4a 1231442 libdevel optional kdelibs4-dev_3.3.2-3_i386.deb
 bd726963e48162feadd5d2e4da22a6bf 18878 kde optional kdelibs_3.3.2-3_all.deb
 099ad360bda1852b227e63f7e4c31d11 7084088 libs optional kdelibs-data_3.3.2-3_all.deb
 c0119c932f491560d9d30debfc5d5ed8 11570728 doc optional kdelibs4-doc_3.3.2-3_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)
Comment: Signed by Isaac Clerencia <isaac@warp.es>

iD8DBQFCIyPAQET2GFTmct4RAskjAKCILG7ab/ww/lpB3ZjqWTx/nzPRLQCdEGdd
GcsTZW2fm6wN4lugq0UGBww=
=VAQa
-----END PGP SIGNATURE-----



Reply to: