CVE-2010-4000

Related Vulnerabilities: CVE-2010-4000  

Debian Bug report logs - #605098
CVE-2010-4000

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Sat, 27 Nov 2010 12:15:11 UTC

Severity: grave

Tags: security

Found in version gnome-shell/2.31.5-1

Fixed in version gnome-shell/2.91.3-1

Done: Emilio Pozuelo Monfort <pochu@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://bugzilla.gnome.org/show_bug.cgi?id=637378

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Gustavo Noronha Silva <gustavo.noronha@collabora.co.uk>:
Bug#605098; Package gnome-shell. (Sat, 27 Nov 2010 12:15:14 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Gustavo Noronha Silva <gustavo.noronha@collabora.co.uk>. (Sat, 27 Nov 2010 12:15:14 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2010-4000
Date: Sat, 27 Nov 2010 13:13:02 +0100
Package: gnome-shell
Severity: grave
Tags: security

Hi,
please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4000
for a description and a proposed patch.

Cheers,
        Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash




Set Bug forwarded-to-address to 'https://bugzilla.gnome.org/show_bug.cgi?id=637378'. Request was from Laurent Bigonville <bigon@debian.org> to control@bugs.debian.org. (Thu, 16 Dec 2010 10:51:03 GMT) (full text, mbox, link).


Bug Marked as found in versions gnome-shell/2.31.5-1. Request was from Laurent Bigonville <bigon@debian.org> to control@bugs.debian.org. (Thu, 16 Dec 2010 10:51:04 GMT) (full text, mbox, link).


Reply sent to Emilio Pozuelo Monfort <pochu@debian.org>:
You have taken responsibility. (Sun, 19 Dec 2010 00:33:08 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Sun, 19 Dec 2010 00:33:09 GMT) (full text, mbox, link).


Message #14 received at 605098-close@bugs.debian.org (full text, mbox, reply):

From: Emilio Pozuelo Monfort <pochu@debian.org>
To: 605098-close@bugs.debian.org
Subject: Bug#605098: fixed in gnome-shell 2.91.3-1
Date: Sun, 19 Dec 2010 00:32:14 +0000
Source: gnome-shell
Source-Version: 2.91.3-1

We believe that the bug you reported is fixed in the latest version of
gnome-shell, which is due to be installed in the Debian FTP archive:

gnome-shell_2.91.3-1.debian.tar.gz
  to main/g/gnome-shell/gnome-shell_2.91.3-1.debian.tar.gz
gnome-shell_2.91.3-1.dsc
  to main/g/gnome-shell/gnome-shell_2.91.3-1.dsc
gnome-shell_2.91.3-1_amd64.deb
  to main/g/gnome-shell/gnome-shell_2.91.3-1_amd64.deb
gnome-shell_2.91.3.orig.tar.gz
  to main/g/gnome-shell/gnome-shell_2.91.3.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 605098@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emilio Pozuelo Monfort <pochu@debian.org> (supplier of updated gnome-shell package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 19 Dec 2010 00:08:30 +0000
Source: gnome-shell
Binary: gnome-shell
Architecture: source amd64
Version: 2.91.3-1
Distribution: experimental
Urgency: low
Maintainer: Gustavo Noronha Silva <gustavo.noronha@collabora.co.uk>
Changed-By: Emilio Pozuelo Monfort <pochu@debian.org>
Description: 
 gnome-shell - graphical shell for the GNOME desktop
Closes: 605098
Changes: 
 gnome-shell (2.91.3-1) experimental; urgency=low
 .
   [ Emilio Pozuelo Monfort ]
   * New upstream release (Closes: #605098, CVE-2010-4000).
     - debian/control.in:
       + Updated dependencies and build dependencies.
     - debian/patches/02_undo_gtk3_transition.diff:
       + Removed, let's use GTK+3 from now on.
     - debian/patches/03_fix_dconf_service_location.diff:
       + Updated.
   * debian/control.in,
     debian/rules:
     - Remove hack to get the typelibs scanned. Pass the private
       directory to dh_girepository instead. Update the minimum
       build dependency on gobject-introspection accordingly.
   * debian/control.in:
     - Build depend on gir1.2 packages.
     - Remove gir dependencies, they are autogenerated.
 .
   [ Laurent Bigonville ]
   * debian/control.in: Add Vcs-* fields
   * debian/watch: Add watch file
 .
   [ Emilio Pozuelo Monfort ]
   * debian/patches/02_fix_build_with_latest_gtk.patch:
     - Patch from upstream git, fix build with GTK+ 2.91.6.
   * debian/control.in:
     - Bump the libgtk3.0-dev accordingly.
   * debian/patches/*.diff:
     - Renamed to debian/patches/*.patch.
Checksums-Sha1: 
 f8d3285792c0663ca112389c35823eae8a75f981 2191 gnome-shell_2.91.3-1.dsc
 39b0ebbbf7b20b96ecd4fec77a132ff478aef60e 1070373 gnome-shell_2.91.3.orig.tar.gz
 b9c63c3c6e1b4ac451896317d5f833767ab740d9 137280 gnome-shell_2.91.3-1.debian.tar.gz
 a93425de3555bc4b3d18b49dc7d49626707e7b86 751470 gnome-shell_2.91.3-1_amd64.deb
Checksums-Sha256: 
 4ee1cae4b4a6401a45794c0451c9a27de205776c37bad28c312a7336d0507174 2191 gnome-shell_2.91.3-1.dsc
 d5b6ccb925adfa63d99072a434b246b46aa517668e0c1fda17c4fe95a60634b0 1070373 gnome-shell_2.91.3.orig.tar.gz
 348b232d25d355a267c8bf254c450d3f54fde2925ee3532346865d56b5f1f736 137280 gnome-shell_2.91.3-1.debian.tar.gz
 176a84c629e2422922841c321733496e17a7acf41a69202919d16bcca656df8d 751470 gnome-shell_2.91.3-1_amd64.deb
Files: 
 d1caeabcd7ba137e1b48cc9cfcef972c 2191 gnome extra gnome-shell_2.91.3-1.dsc
 d88e3e97a90be61bf0c81b529025a389 1070373 gnome extra gnome-shell_2.91.3.orig.tar.gz
 da80cb6fb2d9d30af9cdbceb09dac451 137280 gnome extra gnome-shell_2.91.3-1.debian.tar.gz
 6fedb73029ee5b0b06230d0ab1b2e188 751470 gnome extra gnome-shell_2.91.3-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAk0NTv4ACgkQhTV17EoIsv7bkACgmzpnnG2600RLb1695XXeFoP8
DB8An2mQA1n1bq5+rE5KAFrSfsXOad9S
=rtfA
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 16 Jan 2011 07:34:01 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:41:24 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.