[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#408413: marked as done ((no subject))

Your message dated Wed, 07 Feb 2007 02:32:10 +0000
with message-id <E1HEcbS-0006VY-Fy@ries.debian.org>
and subject line Bug#408413: fixed in kdelibs 4:3.5.5a.dfsg.1-6
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Subject: akregator: crashes when reloading a previously 404 non-html file
Package: akregator
Version: 4:3.5.5.dfsg.1-4
Severity: normal

*** Please type your report below this line ***

not easy to reproduce:
click on a link to a non-html which does not exist on the server.
in my case tested with a .mov and a .wmv file. default behaviour is a dialog 
which asks if I want to save the file or open it with kaffeine.
but since akregator gets a html response because the file doesn't exist a
new tab is opened which says so.

now make the file available on the server.
right click on the 404 message and reload the site -> crash

I could reproduce this more than once because my proxy server(or konqueror?) 
still cached
the 404. but I can't now without setting up an own http server so I can't
provide a stack trace atm.

this might affect other applications using khtml as well I suppose.

akregator was used as part of kontact.

-- System Information:
Debian Release: 4.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.16
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)

Versions of packages akregator depends on:
ii  kdelibs4c2a            4:3.5.5a.dfsg.1-5 core libraries and binaries for 
ii  libc6                  2.3.6.ds1-8       GNU C Library: Shared libraries
ii  libgcc1                1:4.1.1-21        GCC support library
ii  libkdepim1a            4:3.5.5.dfsg.1-4  KDE PIM library
ii  libqt3-mt              3:3.3.7-2         Qt GUI Library (Threaded runtime 
ii  libstdc++6             4.1.1-21          The GNU Standard C++ Library v3

akregator recommends no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: kdelibs
Source-Version: 4:3.5.5a.dfsg.1-6

We believe that the bug you reported is fixed in the latest version of
kdelibs, which is due to be installed in the Debian FTP archive:

  to pool/main/k/kdelibs/kdelibs-data_3.5.5a.dfsg.1-6_all.deb
  to pool/main/k/kdelibs/kdelibs-dbg_3.5.5a.dfsg.1-6_i386.deb
  to pool/main/k/kdelibs/kdelibs4-dev_3.5.5a.dfsg.1-6_i386.deb
  to pool/main/k/kdelibs/kdelibs4-doc_3.5.5a.dfsg.1-6_all.deb
  to pool/main/k/kdelibs/kdelibs4c2a_3.5.5a.dfsg.1-6_i386.deb
  to pool/main/k/kdelibs/kdelibs_3.5.5a.dfsg.1-6.diff.gz
  to pool/main/k/kdelibs/kdelibs_3.5.5a.dfsg.1-6.dsc
  to pool/main/k/kdelibs/kdelibs_3.5.5a.dfsg.1-6_all.deb

A summary of the changes between this version and the previous one is

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 408413@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> (supplier of updated kdelibs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)

Hash: SHA1

Format: 1.7
Date: Wed, 17 Jan 2007 09:55:20 -0500
Source: kdelibs
Binary: kdelibs4c2a kdelibs kdelibs4-doc kdelibs-dbg kdelibs-data kdelibs4-dev
Architecture: source i386 all
Version: 4:3.5.5a.dfsg.1-6
Distribution: unstable
Urgency: high
Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Changed-By: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
 kdelibs    - core libraries from the official KDE release
 kdelibs-data - core shared data for all KDE applications
 kdelibs-dbg - debugging symbols for kdelibs
 kdelibs4-dev - development files for the KDE core libraries
 kdelibs4-doc - developer documentation for the KDE core libraries
 kdelibs4c2a - core libraries and binaries for all KDE applications
Closes: 407272 408413 409868
 kdelibs (4:3.5.5a.dfsg.1-6) unstable; urgency=high
   +++ Changes by Ana Beatriz Guerrero Lopez:
   * Add patch 45_konqueror-CVE-2007-0537.diff which fixes: Konqueror does not
     properly parse HTML comments, which allows remote attackers to conduct
     cross-site scripting (XSS) attacks. CVE-2007-0537. (Closes: #409868).
     Thanks to Kees Cook for reporting and pointing to the fix.
   +++ Changes by Modestas Vainius:
   * New patch (No. 25) from KDE bug #128564. Fixes khtml crash on loading
     some non existing pages when javascript is disabled (Closes: #408413).
     Probably fixes these KDE bugs too: #126812, #127137, #135117, #138449.
   * Add libc6-dbg to kdelibs-dbg dependencies on amd64. It seems to be
     needed to get a useful backtrace from drkonqi on this arch.
   +++ Changes by Josh Metzler:
   * Add 44_sync_kwallet_changes to make kwallet write changes to disk
     immediately, avoiding losing passwords if kwallet doesn't shutdown
     cleanly.  (Closes: #407272)
 dfd18bd4d9bfbabcf06bd513ea133de3 1617 libs optional kdelibs_3.5.5a.dfsg.1-6.dsc
 e068f1839d651639e6192451bb72cc71 592375 libs optional kdelibs_3.5.5a.dfsg.1-6.diff.gz
 5eefa15aa79179c70aa0ba68c2a2620f 33962 libs optional kdelibs_3.5.5a.dfsg.1-6_all.deb
 2fcca2a2fe773592a5a73af70ba52ff5 8456324 libs optional kdelibs-data_3.5.5a.dfsg.1-6_all.deb
 07e942d7fb9f4814d5e3f8763d5663dd 38881862 doc optional kdelibs4-doc_3.5.5a.dfsg.1-6_all.deb
 4770540f25b2d130cfc7ff18c9fbfcb4 9733762 libs optional kdelibs4c2a_3.5.5a.dfsg.1-6_i386.deb
 9f1752055a7048f1497e4d18c39e76e1 1338988 libdevel optional kdelibs4-dev_3.5.5a.dfsg.1-6_i386.deb
 ac0fd0f0d8440cb2fbc123b41cb0714b 26254740 libdevel extra kdelibs-dbg_3.5.5a.dfsg.1-6_i386.deb

Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Signed by Ana Guerrero


--- End Message ---

Reply to: