CVE-2007-0317: format string vulnerabilities

Related Vulnerabilities: CVE-2007-0317  

Debian Bug report logs - #407683
CVE-2007-0317: format string vulnerabilities

version graph

Reported by: Florian Weimer <fw@deneb.enyo.de>

Date: Sat, 20 Jan 2007 14:18:02 UTC

Severity: grave

Tags: security

Found in version filezilla/3.0.0~beta2-2

Fixed in version filezilla/3.0.0~beta2-3

Done: Adam Cécile (Le_Vert) <gandalf@le-vert.net>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Adam Cécile (Le_Vert) <gandalf@le-vert.net>:
Bug#407683; Package filezilla. (full text, mbox, link).


Acknowledgement sent to Florian Weimer <fw@deneb.enyo.de>:
New Bug report received and forwarded. Copy sent to Adam Cécile (Le_Vert) <gandalf@le-vert.net>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Florian Weimer <fw@deneb.enyo.de>
To: submit@bugs.debian.org
Subject: CVE-2007-0317: format string vulnerabilities
Date: Sat, 20 Jan 2007 14:48:24 +0100
Package: filezilla
Version: 3.0.0~beta2-2
Tags: security
Severity: grave

Upstream fixed format string issues in 3.0.0-beta5.  Please upgrade to
that version (or backport the changes).  Don't forget to mention
CVE-2007-0317 in the changelog when fixing this bug.  Thanks!



Reply sent to Adam Cécile (Le_Vert) <gandalf@le-vert.net>:
You have taken responsibility. (full text, mbox, link).


Notification sent to Florian Weimer <fw@deneb.enyo.de>:
Bug acknowledged by developer. (full text, mbox, link).


Message #10 received at 407683-close@bugs.debian.org (full text, mbox, reply):

From: Adam Cécile (Le_Vert) <gandalf@le-vert.net>
To: 407683-close@bugs.debian.org
Subject: Bug#407683: fixed in filezilla 3.0.0~beta2-3
Date: Sun, 21 Jan 2007 05:21:27 +0000
Source: filezilla
Source-Version: 3.0.0~beta2-3

We believe that the bug you reported is fixed in the latest version of
filezilla, which is due to be installed in the Debian FTP archive:

filezilla-common_3.0.0~beta2-3_all.deb
  to pool/main/f/filezilla/filezilla-common_3.0.0~beta2-3_all.deb
filezilla-locales_3.0.0~beta2-3_all.deb
  to pool/main/f/filezilla/filezilla-locales_3.0.0~beta2-3_all.deb
filezilla_3.0.0~beta2-3.diff.gz
  to pool/main/f/filezilla/filezilla_3.0.0~beta2-3.diff.gz
filezilla_3.0.0~beta2-3.dsc
  to pool/main/f/filezilla/filezilla_3.0.0~beta2-3.dsc
filezilla_3.0.0~beta2-3_i386.deb
  to pool/main/f/filezilla/filezilla_3.0.0~beta2-3_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 407683@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adam Cécile (Le_Vert) <gandalf@le-vert.net> (supplier of updated filezilla package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sat, 20 Jan 2007 18:11:31 +0100
Source: filezilla
Binary: filezilla-locales filezilla-common filezilla
Architecture: source i386 all
Version: 3.0.0~beta2-3
Distribution: unstable
Urgency: high
Maintainer: Adam Cécile (Le_Vert) <gandalf@le-vert.net>
Changed-By: Adam Cécile (Le_Vert) <gandalf@le-vert.net>
Description: 
 filezilla  - Port of the famous Win32 graphical FTP client
 filezilla-common - Architecture independent files for filezilla
 filezilla-locales - Translations of filezilla
Closes: 407683
Changes: 
 filezilla (3.0.0~beta2-3) unstable; urgency=HIGH
 .
   * Backport patch from filezilla 3.0.0~beta5 to fix format string
     vulnerabilities, see CVE-2007-0317 (Closes: #407683).
   * Add dpatch build-dependency to handle patches.
Files: 
 91a510955865616e0d54a1f1c5ca0384 744 net optional filezilla_3.0.0~beta2-3.dsc
 b355a82d73d2f046d1cda92ded53780f 33410 net optional filezilla_3.0.0~beta2-3.diff.gz
 f34b4249acaca6fbe5c76f0502f0c8ee 693328 net optional filezilla_3.0.0~beta2-3_i386.deb
 b353bfaf6d622464b20127e09991d8b2 36874 net optional filezilla-common_3.0.0~beta2-3_all.deb
 c7304a200b209aea533a2bf975a8f6f6 628926 net optional filezilla-locales_3.0.0~beta2-3_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFFslUi+C5cwEsrK54RAj9uAJ4z8A8/lIWmMKLc7BqjHdtK5OtLOgCfcX9J
sgOr7oSGI052NLHBijhzmfo=
=mVZK
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 26 Jun 2007 20:25:12 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 13:48:57 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.